Техническая информация
- '%WINDIR%\syswow64\wscript.exe' "%APPDATA%\Xgsytplj.vbs"
- %TEMP%\mz_etilqs_sqfan69n62cu4oh
- %TEMP%\mz_etilqs_vrm0w2tonwsuq3z
- %APPDATA%\xgsytplj.vbs
- %TEMP%\mz_etilqs_3eqeplgfigsofrg
- '34.##0.144.191':443
- 'fi#######torage.googleapis.com':443
- 'pk#.goog':80
- 'fe########alog-cdn.prod.mozaws.net':443
- http://pk#.goog/gsr1/gsr1.crt
- '34.##0.144.191':443
- 'fi#######torage.googleapis.com':443
- DNS ASK fi#######torage.googleapis.com
- DNS ASK pk#.goog
- DNS ASK fe########alog-cdn.prod.mozaws.net
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' [Byte[]] $rOWg = [system.Convert]::FromBase64string('TVqQAAMAAAAEAAAA//8AALgAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAgAAAAA4fug4AtAnNIbgBTM0hVGhpcyBwcm9ncmFtIGNhbm5vdCBiZSBydW4g...' (со скрытым окном)
- '%CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe' -Embedding
- '<SYSTEM32>\searchprotocolhost.exe' Global\UsGthrFltPipeMssGthrPipe5_ Global\UsGthrCtrlFltPipeMssGthrPipe5 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "%...
- '<SYSTEM32>\searchfilterhost.exe' 0 508 512 520 65536 516