Техническая информация
- %HOMEPATH%\Start Menu\Programs\Startup\cb096cc5954244515fbe784d950d1626.exe
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] '%TEMP%\serverout.exe' = '%TEMP%\serverout.exe:*:Enabled:serverout.exe'
- '%TEMP%\serverout.exe'
- '<SYSTEM32>\netsh.exe' firewall add allowedprogram "%TEMP%\serverout.exe" "serverout.exe" ENABLE
- %TEMP%\serverout.exe
- 'mr####a.ddns.net':5552
- DNS ASK mr####a.ddns.net