Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Xrhfmjp' = '"%APPDATA%\Qjovnqqka\Xrhfmjp.exe"'
- %APPDATA%\qjovnqqka\xrhfmjp.exe
- '79.##2.69.160':24103
- 'localhost':24103
- '10.#.239.161':24103
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -ENC cwB0AGEAcgB0AC0AcwBsAGUAZQBwACAALQBzAGUAYwBvAG4AZABzACAAMgAwAA==' (со скрытым окном)
- '%WINDIR%\syswow64\cmd.exe' /c powershell -ENC cwBlAHQALQBtAHAAcAByAGUAZgBlAHIAZQBuAGMAZQAgAC0AZQB4AGMAbAB1AHMAaQBvAG4AcABhAHQAaAAgAEMAOgBcAA==' (со скрытым окном)
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -ENC cwB0AGEAcgB0AC0AcwBsAGUAZQBwACAALQBzAGUAYwBvAG4AZABzACAAMgAwAA==
- '%WINDIR%\syswow64\cmd.exe' /c powershell -ENC cwBlAHQALQBtAHAAcAByAGUAZgBlAHIAZQBuAGMAZQAgAC0AZQB4AGMAbAB1AHMAaQBvAG4AcABhAHQAaAAgAEMAOgBcAA==
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -ENC cwBlAHQALQBtAHAAcAByAGUAZgBlAHIAZQBuAGMAZQAgAC0AZQB4AGMAbAB1AHMAaQBvAG4AcABhAHQAaAAgAEMAOgBcAA==