Техническая информация
- <SYSTEM32>\tasks\test.exe
- %APPDATA%\test.exe
- '19#.#3.199.56':56001
- '19#.#3.199.56':56002
- '19#.#3.199.56':56003
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -NoProfile -ExecutionPolicy Bypass -Enc UgBlAGcAaQBzAHQAZQByAC0AUwBjAGgAZQBkAHUAbABlAGQAVABhAHMAawAgAC0AVABhAHMAawBOAGEAbQBlACAAJwB0AGUAcwB0AC4AZQB4AGUAJwAgAC0AQQBjAHQAaQBvAG4AIAAoAE4AZQB3AC0AU...