Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD JABLAHkATwA4AHEARQAgAD0AIABbAHQAWQBwAGUAXQAoACIAewAxAH0AewAzAH0AewAyAH0AewA0AH0AewAwAH0AIgAgAC0ARgAnAHIAeQAnACwAJwBzAFkAUwBUACcALAAnAEQASQBSACcALAAnAEUATQAuAEkATwAuACcALA...
- %TEMP%\1109510.cvr
- %HOMEPATH%\qja7l6t\dz0li3c\mwew2pan.exe
- 'io####bhosting.com':80
- 'we###chieu.com':443
- 'ma###.#eb.unib.ac.id':80
- http://io####bhosting.com/cgi-bin/8li/
- http://www.io####bhosting.com/cgi-bin/8li/
- http://ma###.#eb.unib.ac.id/wp-admin/qFFKjLkYnc/
- 'we###chieu.com':443
- DNS ASK io####bhosting.com
- DNS ASK we###chieu.com
- DNS ASK ma###.#eb.unib.ac.id
- DNS ASK he######harmaceutical.com
- DNS ASK ha###boy.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD JABLAHkATwA4AHEARQAgAD0AIABbAHQAWQBwAGUAXQAoACIAewAxAH0AewAzAH0AewAyAH0AewA0AH0AewAwAH0AIgAgAC0ARgAnAHIAeQAnACwAJwBzAFkAUwBUACcALAAnAEQASQBSACcALAAnAEUATQAuAEkATwAuACcALA... (со скрытым окном)