Техническая информация
- [<HKLM>\System\CurrentControlSet\Services\metricskhmer] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\metricskhmer] 'ImagePath' = '"%WINDIR%\SysWOW64\metricskhmer.exe"'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABBAHoAeQB0AGoAaAB6AGcAYQB1AG0AaQBnAD0AJwBOAHYAeABkAHgAZwBjAGMAYgBuAGcAJwA7ACQATgBuAHkAagB0AGgAYwByAHoAagBvAHkAdgAgAD0AIAAnADkAMwA3ACcAOwAkAEkAaQBxAHMAZgBwAHMAbQA9ACcAUgBvAGcAeAB...
- %HOMEPATH%\937.exe
- %HOMEPATH%\937.exe в %WINDIR%\syswow64\metricskhmer.exe
- http://ah#.#rbdev.com/wp-admin/qp0/
- http://68.##4.229.171/AHvI
- DNS ASK ah#.#rbdev.com
- '%HOMEPATH%\937.exe'
- '%WINDIR%\syswow64\metricskhmer.exe'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABBAHoAeQB0AGoAaAB6AGcAYQB1AG0AaQBnAD0AJwBOAHYAeABkAHgAZwBjAGMAYgBuAGcAJwA7ACQATgBuAHkAagB0AGgAYwByAHoAagBvAHkAdgAgAD0AIAAnADkAMwA3ACcAOwAkAEkAaQBxAHMAZgBwAHMAbQA9ACcAUgBvAGcAeAB...' (со скрытым окном)