Техническая информация
- [<HKLM>\System\CurrentControlSet\Services\zapserial] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\zapserial] 'ImagePath' = '"<SYSTEM32>\zapserial.exe"'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABYAGgAYQB6AHoAdwB4AGkAbQBoAGsAcQA9ACcAQQB6AHkAYwBjAGkAcAB0AGsAaQB3ACcAOwAkAEcAZwBzAHIAcQBvAG4AdAByAHgAaAAgAD0AIAAnADkANAA4ACcAOwAkAFMAdwBsAG8AZQBqAGUAaABuAGUAegA9ACcASAB0AHkAaQB...
- %HOMEPATH%\948.exe
- %HOMEPATH%\948.exe в <SYSTEM32>\zapserial.exe
- http://ne###perty.in/cgi-bin/hjjz1r5p-5n7mea41-7609513198/
- http://59.###.126.129:443/2H1JQmwpyGgCdejxM via 59.##5.126.129
- DNS ASK ok##eo.com
- DNS ASK ko##ata.com
- DNS ASK pa#####ngtopsecrets.com
- DNS ASK ne###perty.in
- DNS ASK mc####.#00webhostapp.com
- '%HOMEPATH%\948.exe'
- '<SYSTEM32>\zapserial.exe'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABYAGgAYQB6AHoAdwB4AGkAbQBoAGsAcQA9ACcAQQB6AHkAYwBjAGkAcAB0AGsAaQB3ACcAOwAkAEcAZwBzAHIAcQBvAG4AdAByAHgAaAAgAD0AIAAnADkANAA4ACcAOwAkAFMAdwBsAG8AZQBqAGUAaABuAGUAegA9ACcASAB0AHkAaQB...' (со скрытым окном)