Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'C90PEmoW' = '%ALLUSERSPROFILE%\O8I9nCCrYLWBZ\E47XDFVgbfkIXZb\gN4hAJMlXg5ozt\A07dN2imd05OLhX\kGEthQQIrHQF\WCQ5dFl5NUhT\3EI3LsB3.exe'
- '%ALLUSERSPROFILE%\O8I9nCCrYLWBZ\E47XDFVgbfkIXZb\gN4hAJMlXg5ozt\A07dN2imd05OLhX\kGEthQQIrHQF\WCQ5dFl5NUhT\3EI3LsB3.exe'
- %ALLUSERSPROFILE%\O8I9nCCrYLWBZ\E47XDFVgbfkIXZb\gN4hAJMlXg5ozt\A07dN2imd05OLhX\kGEthQQIrHQF\WCQ5dFl5NUhT\3EI3LsB3.exe
- %ALLUSERSPROFILE%\88270c99ad172825a294c3e4179f1f4ac43cd6cd
- %ALLUSERSPROFILE%\O8I9nCCrYLWBZ\E47XDFVgbfkIXZb\gN4hAJMlXg5ozt\A07dN2imd05OLhX\kGEthQQIrHQF\WCQ5dFl5NUhT\3EI3LsB3.exe
- 'dl.##opbox.com':80
- dl.##opbox.com/u/24080239/test.txt
- DNS ASK dl.##opbox.com
- DNS ASK www.ps###lo.co.cc
- ClassName: 'Indicator' WindowName: '(null)'