Техническая информация
- <SYSTEM32>\tasks\guild mergers.exe
- %LOCALAPPDATA%\guild mergers.exe
- '45.##4.98.15':56001
- '45.##4.98.15':56002
- '45.##4.98.15':56003
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -NoProfile -ExecutionPolicy Bypass -Enc UgBlAGcAaQBzAHQAZQByAC0AUwBjAGgAZQBkAHUAbABlAGQAVABhAHMAawAgAC0AVABhAHMAawBOAGEAbQBlACAAJwBHAHUAaQBsAGQAIABtAGUAcgBnAGUAcgBzAC4AZQB4AGUAJwAgAC0AQQBjAHQAa...