Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\RunOnce] 'dwdpxnapUfBe' = 'explorer.exe "%WINDIR%\Microsoft.NET\Framework\rqGLirhmXUABnRYtvOkefUEOVSuz\svchost.exe"'
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows Defender\Exclusions\Paths] '%WINDIR%\Microsoft.NET\Framework\rqGLirhmXUABnRYtvOkefUEOVSuz\svchost.exe' = '00000000'
- %WINDIR%\microsoft.net\framework\rqglirhmxuabnrytvokefueovsuz\svchost.exe
- '19#.#36.147.189':80
- 'ch####p.dyndns.org':80
- 'fr###eoip.app':443
- http://19#.#36.147.189/custom/alien/html/base/703BCFF91D88F41D7B7343972FA34B73.html
- http://19#.#36.147.189/custom/alien/html/base/8F85B92FD45A8372609CA33ED2E32BBC.html
- DNS ASK ch####p.dyndns.org
- DNS ASK fr###eoip.app
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' Add-MpPreference -ExclusionPath "%WINDIR%\Microsoft.NET\Framework\rqGLirhmXUABnRYtvOkefUEOVSuz\svchost.exe" -Force' (со скрытым окном)
- '%WINDIR%\syswow64\cmd.exe' /c timeout 1' (со скрытым окном)
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' Add-MpPreference -ExclusionPath "%WINDIR%\Microsoft.NET\Framework\rqGLirhmXUABnRYtvOkefUEOVSuz\svchost.exe" -Force
- '%WINDIR%\syswow64\cmd.exe' /c timeout 1
- '%WINDIR%\syswow64\timeout.exe' 1