Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'SonyAgent' = '<Полный путь к вирусу>'
- '<SYSTEM32>\conhost.exe'
- <Полный путь к вирусу>
- 'localhost':49202
- '77.##1.93.153':80
- '37.##.233.23':80
- '10#.#6.52.102':80
- 'localhost':49205
- '17#.#58.238.3':80
- 'localhost':49193
- 'localhost':49196
- 'localhost':49199
- '77.##2.60.55':80
- 'localhost':49208
- '12#.6.5.23':80
- 'localhost':49217
- '17#.#24.13.37':80
- '10#.#6.64.35':80
- '20#.#57.41.6':80
- 'localhost':49211
- '77.##2.18.241':80
- '76.##.127.15':80
- '18#.#30.20.84':80
- 'localhost':49214
- '5.##8.2.82':80
- 'localhost':49169
- '21#.#20.148.43':80
- '37.##9.104.144':80
- '22#.#8.242.15':80
- 'localhost':49172
- '15#.#24.128.7':80
- 'localhost':49160
- 'localhost':49163
- 'localhost':49166
- '31.##9.97.212':80
- 'localhost':49175
- '77.#1.7.76':80
- 'localhost':49184
- 'localhost':49187
- 'localhost':49190
- '5.###.248.13':80
- 'localhost':49178
- '46.##.154.89':80
- '11#.#1.62.237':80
- '93.#7.51.13':80
- 'localhost':49181
- 10#.#6.64.35/file.htm
- 20#.#57.41.6/install.htm
- 17#.#24.13.37/default.htm