Техническая информация
- '%APPDATA%\Roaming\ID Detector\detect.exe'
- %APPDATA%\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ID Detector.vbs
- %APPDATA%\Roaming\ID Detector\detect.bat
- %APPDATA%\Roaming\ID Detector\detect.exe
- 'co##.#lory297.org':1708
- DNS ASK dn#.##ftncsi.com
- DNS ASK co##.#lory297.org