Техническая информация
- 'rasman' "%WINDIR%\SysWOW64\iprop\rasman.exe"
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD JABTAGMAaAA0AHoAagAyAD0AKAAnAFoAXwAnACsAKAAnAHoAcgAnACsAJwBqADMAYQAnACkAKQA7AC4AKAAnAG4AZQB3AC0AaQB0ACcAKwAnAGUAJwArACcAbQAnACkAIAAkAEUAbgBWADoAVQBzAEUAUgBQAFIATwBmAGkAbA...
- %HOMEPATH%\ic4egvu\c_zsk5x\bp6p4xpk.exe
- %WINDIR%\syswow64\iprop\rasman.exe
- %HOMEPATH%\ic4egvu\c_zsk5x\bp6p4xpk.exe в %WINDIR%\syswow64\iprop\rasman.exe
- '12.##3.208.58':80
- '45.#3.35.74':8080
- '87.##6.253.248':8080
- '19#.#41.146.84':8080
- http://ib###lobal.com/thankyou2/ARA/
- http://12.##3.208.58/22Ps/
- http://87.###.253.248:8080/lmZRJgvEKihuNKIP4HY/BOyhqEU/gZU1BBIDB9o8BxLPj/qMCZVrEWUnn40R/xG045M73KVWZLVP/mytJT21kJ4doZ/ via 87.##6.253.248
- http://19#.##1.146.84:8080/B5CJXMF2VieBw/EPIFnijTZZL06/yD69trbfk8fZNz/Kqx2b/ via 19#.#41.146.84
- DNS ASK ib###lobal.com
- '%HOMEPATH%\ic4egvu\c_zsk5x\bp6p4xpk.exe'
- '%WINDIR%\syswow64\iprop\rasman.exe'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD JABTAGMAaAA0AHoAagAyAD0AKAAnAFoAXwAnACsAKAAnAHoAcgAnACsAJwBqADMAYQAnACkAKQA7AC4AKAAnAG4AZQB3AC0AaQB0ACcAKwAnAGUAJwArACcAbQAnACkAIAAkAEUAbgBWADoAVQBzAEUAUgBQAFIATwBmAGkAbA...' (со скрытым окном)