Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Microsoft Securitys Firewall 1.0.0' = '%TEMP%\1.0.0_security_fire.exe'
- '%TEMP%\1.0.0_security_fire.exe'
- %TEMP%\1.0.0_security_fire.exe
- 'ma###ting.com':80
- 'wp#d':80
- ma###ting.com/xbot/hucum.php?44################
- ma###ting.com/xbot/hucum.php?76################
- ma###ting.com/xbot/hucum.php?15##################
- ma###ting.com/xbot/hucum.php?33################
- ma###ting.com/xbot/hucum.php?10##################
- ma###ting.com/xbot/versiya.php?21##################
- wp#d/wpad.dat
- ma###ting.com/xbot/hucum.php?96##############
- ma###ting.com/xbot/hucum.php?19##################
- ma###ting.com/xbot/hucum.php?11##################
- DNS ASK ma###ting.com
- DNS ASK wp#d
- ClassName: 'Indicator' WindowName: '(null)'