Техническая информация
- '<SYSTEM32>\conhost.exe'
- %WINDIR%\Temp\MPTelemetrySubmit\client_manifest.txt
- %WINDIR%\Temp\MPTelemetrySubmit\watson_manifest.txt
- <LS_APPDATA>\Microsoft\Windows\Temporary Internet Files\Content.IE5\BOWDBRP7\sistem3[1].hlp
- %PROGRAM_FILES%\1A3l2D\1W6V6m6c6M.7O2U6Y5a
- 'dl.##opbox.com':80
- 'localhost':65258
- dl.##opbox.com/s/tfyv78ed3ww0ico/sistem3.hlp?dl##
- DNS ASK wa####.microsoft.com
- DNS ASK dl.##opbox.com
- '22#.0.0.252':5355