Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'C8B26A0F' = '%APPDATA%\C8B26A0F\bin.exe'
- '%WINDIR%\explorer.exe'
- <SYSTEM32>\cscript.exe
- %APPDATA%\C8B26A0F\bin.exe
- %APPDATA%\C8B26A0F\log.dat
- 'g0#####26yenz63om.cc':80
- http://g0#####26yenz63om.cc/go8dj37dh672bxj8j8ld/
- DNS ASK g0#####26yenz63om.cc
- ClassName: 'Indicator' WindowName: ''