Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABQAHkAbAA4ADIAeQBzAD0AKAAnAEUAbgAnACsAKAAnAHoANwAnACsAJwBpADEAdQAnACkAKQA7AC4AKAAnAG4AZQB3ACcAKwAnAC0AaQB0AGUAJwArACcAbQAnACkAIAAkAEUATgB2ADoAVABFAG0AUABcAHcAbwBSAEQAXAAyADAAMQA5AFwAIAAtAG...
- %TEMP%\word\2019\hvxgr8gx7.exe
- http://fa##e.fr/wp-admin/file/FAbuFjTiekl/
- http://cy####sbrook.com/wp-content/VeoMiVnkau/
- http://www.cy####sbrook.com/wp-content/VeoMiVnkau/
- http://pr#####leadership.com/think/37sb365521630/
- http://ra####tisitma.com/wp-includes/attach/tYnW/
- http://ra####tisitma.com/cgi-sys/suspendedpage.cgi
- DNS ASK ga######reenscreen.co.uk
- DNS ASK fa##e.fr
- DNS ASK kr##8.top
- DNS ASK cy####sbrook.com
- DNS ASK pr#####leadership.com
- DNS ASK mi###h2u.com
- DNS ASK ra####tisitma.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABQAHkAbAA4ADIAeQBzAD0AKAAnAEUAbgAnACsAKAAnAHoANwAnACsAJwBpADEAdQAnACkAKQA7AC4AKAAnAG4AZQB3ACcAKwAnAC0AaQB0AGUAJwArACcAbQAnACkAIAAkAEUATgB2ADoAVABFAG0AUABcAHcAbwBSAEQAXAAyADAAMQA5AFwAIAAtAG...' (со скрытым окном)