Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Iwzce' = '"%APPDATA%\Dehmd\Iwzce.exe"'
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'Load' = '%ALLUSERSPROFILE%\images.exe'
- %WINDIR%\microsoft.net\framework\v4.0.30319\msbuild.exe
- %WINDIR%\microsoft.net\framework\v4.0.30319\msbuild.exe
- %APPDATA%\dehmd\iwzce.exe
- %ALLUSERSPROFILE%\images.exe
- 'ba######6-59-73.ngrok.io':80
- http://ba######6-59-73.ngrok.io/download/Dkqvmp_Hbeedtgg.bmp
- DNS ASK ba######6-59-73.ngrok.io
- '%ALLUSERSPROFILE%\images.exe'
- '%WINDIR%\syswow64\cmd.exe' /c REG ADD "HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows" /f /v Load /t REG_SZ /d "%ALLUSERSPROFILE%\images.exe"' (со скрытым окном)
- '%WINDIR%\syswow64\cmd.exe' /c timeout 10' (со скрытым окном)
- '%WINDIR%\syswow64\cmd.exe' /c timeout 10
- '%WINDIR%\syswow64\timeout.exe' 10
- '%WINDIR%\microsoft.net\framework\v4.0.30319\msbuild.exe'
- '%WINDIR%\syswow64\cmd.exe' /c REG ADD "HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows" /f /v Load /t REG_SZ /d "%ALLUSERSPROFILE%\images.exe"
- '%WINDIR%\syswow64\reg.exe' ADD "HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows" /f /v Load /t REG_SZ /d "%ALLUSERSPROFILE%\images.exe"