Техническая информация
- [<HKCU>\Software\Microsoft\Windows NT\CurrentVersion\Windows] 'load' = '<Полный путь к вирусу>'
- 'up####.tech-tw.com':80
- 'we#####.bluestartw.com':80
- 'www.pl##k.com':80
- www.pl##k.com/angela888888
- up####.tech-tw.com/VY6CjiMbFliOwc1Z83-ytK
- we#####.bluestartw.com/VY6CjiMbFliOwc1Z83-ytK
- DNS ASK up####.tech-tw.com
- DNS ASK we#####.bluestartw.com
- DNS ASK www.pl##k.com