Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enco JABpAHYAbwByAHkAbQByAHQAPQAnAFMAbQBhAGwAbABfAEYAcgBvAHoAZQBuAF8AQwBoAGEAaQByAGQAbQBmACcAOwAkAEgAYQBuAGQAYwByAGEAZgB0AGUAZABfAE0AZQB0AGEAbABfAEMAaABpAGMAawBlAG4AawBvAGQAIAA9ACAAJwAxADIAOAA...
- DNS ASK oe###onaam.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enco JABpAHYAbwByAHkAbQByAHQAPQAnAFMAbQBhAGwAbABfAEYAcgBvAHoAZQBuAF8AQwBoAGEAaQByAGQAbQBmACcAOwAkAEgAYQBuAGQAYwByAGEAZgB0AGUAZABfAE0AZQB0AGEAbABfAEMAaABpAGMAawBlAG4AawBvAGQAIAA9ACAAJwAxADIAOAA...' (со скрытым окном)