Техническая информация
- <SYSTEM32>\tasks\avtohost.exe
- %APPDATA%\avtohost.exe
- '19#.#6.225.113':56001
- '19#.#6.225.113':56002
- '19#.#6.225.113':56003
- '19#.#6.225.113':33523
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -NoProfile -ExecutionPolicy Bypass -Enc UgBlAGcAaQBzAHQAZQByAC0AUwBjAGgAZQBkAHUAbABlAGQAVABhAHMAawAgAC0AVABhAHMAawBOAGEAbQBlACAAJwBhAHYAdABvAGgAbwBzAHQALgBlAHgAZQAnACAALQBBAGMAdABpAG8AbgAgACgAT...