Техническая информация
- [<HKLM>\System\CurrentControlSet\Services\mexicocreatea] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\mexicocreatea] 'ImagePath' = '"%WINDIR%\SysWOW64\mexicocreatea.exe"'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABRAHEAbgBkAHMAdQBhAHIAZAB6AD0AJwBUAHgAdwBoAGgAbAB1AHAAbQB1AG8AYQAnADsAJABCAGgAYgBiAGkAYgB6AG4AYwBnAGwAcQAgAD0AIAAnADgAMAA1ACcAOwAkAE8AYgBrAGcAYQBvAHQAeABvAGoAbABiAHUAPQAnAEQAYwB4AG8AaQBiAH...
- %HOMEPATH%\805.exe
- %HOMEPATH%\805.exe
- %HOMEPATH%\805.exe в %WINDIR%\syswow64\mexicocreatea.exe
- %HOMEPATH%\805.exe
- http://85.##0.115.92/6bIWol2mU9Yr
- DNS ASK 9j###iss.com
- DNS ASK nv#.##tsmartz.net
- DNS ASK tb########rakat.000webhostapp.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABRAHEAbgBkAHMAdQBhAHIAZAB6AD0AJwBUAHgAdwBoAGgAbAB1AHAAbQB1AG8AYQAnADsAJABCAGgAYgBiAGkAYgB6AG4AYwBnAGwAcQAgAD0AIAAnADgAMAA1ACcAOwAkAE8AYgBrAGcAYQBvAHQAeABvAGoAbABiAHUAPQAnAEQAYwB4AG8AaQBiAH...' (со скрытым окном)