Техническая информация
- [<HKLM>\System\CurrentControlSet\Services\ffrwbdgv.mjq] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\ffrwbdgv.mjq] 'ImagePath' = '%WINDIR%\SysWOW64\regsvr32.exe /s "%WINDIR%\SysWOW64\Nrblqhich\ffrwbdgv.mjq"'
- 'ffrwbdgv.mjq' %WINDIR%\SysWOW64\regsvr32.exe /s "%WINDIR%\SysWOW64\Nrblqhich\ffrwbdgv.mjq"
- '%WINDIR%\syswow64\regsvr32.exe' -s ..\urtj.dll
- %HOMEPATH%\urtj.dll
- <Текущая директория>\ced51000
- %HOMEPATH%\urtj.dll в %WINDIR%\syswow64\nrblqhich\ffrwbdgv.mjq
- <PATH_SAMPLE>.xls
- 'ge###rsh.com':443
- '18#.#57.82.211':8080
- '18#.#4.20.25':443
- '16#.68.99.3':8080
- '15#.#9.222.101':443
- '20#.#89.28.199':8080
- '1.##4.21.73':7080
- '21#.#4.98.99':8080
- '16#.#9.115.35':8080
- '21#.#58.226.206':443
- '79.##3.187.147':443
- '18#.#4.80.182':443
- '13#.#97.109.175':8080
- '10#.#31.11.205':443
- '68.##3.94.239':80
- 'ga#####haliyikama.com':80
- '13#.#22.66.193':8080
- '19#.#18.30.83':443
- http://www.ga#####haliyikama.com/wp-admin/FjgB6I/
- 'ge###rsh.com':443
- '15#.#9.222.101':443
- DNS ASK ge###rsh.com
- DNS ASK ga#####haliyikama.com
- '%WINDIR%\syswow64\regsvr32.exe' -s ..\urtj.dll' (со скрытым окном)
- '%WINDIR%\syswow64\regsvr32.exe' /s "%WINDIR%\SysWOW64\Nrblqhich\ffrwbdgv.mjq"