Техническая информация
- [<HKLM>\System\CurrentControlSet\Services\rustlb] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\rustlb] 'ImagePath' = '"%WINDIR%\SysWOW64\rustlb.exe"'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABXAHUAagBoAG8AbgBqAHUAYgB0AHEAagA9ACcAUgBrAHQAdABhAGoAeABjAGgAagB4ACcAOwAkAE0AcgBrAHYAdQBvAHkAZwBkAG...
- %HOMEPATH%\894.exe
- %HOMEPATH%\894.exe
- %HOMEPATH%\894.exe в %WINDIR%\syswow64\rustlb.exe
- %HOMEPATH%\894.exe
- '10#.#27.100.228':80
- '12#.#38.101.250':80
- '13#.#.103.200':8080
- http://ks.#d.ua/wp-includes/KXdkADm/
- http://19#.##.118.15:443/merge/loadan/ringin/merge/ via 19#.#6.118.15
- DNS ASK li###more.tk
- DNS ASK ig###istics.in
- DNS ASK su####roshomes.com
- DNS ASK ks.#d.ua
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e PAAjACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvACAAIwA+ACAAJABXAHUAagBoAG8AbgBqAHUAYgB0AHEAagA9ACcAUgBrAHQAdABhAGoAeABjAGgAagB4ACcAOwAkAE0AcgBrAHYAdQBvAHkAZwBkAG...' (со скрытым окном)