Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '9h8o2dqnsL6u5DD' = '%APPDATA%\dgt76t67sadt.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] '9h8o2dqnsL6u5DD' = '%APPDATA%\dgt76t67sadt.exe'
- '%APPDATA%\dgt76t67sadt.exe'
- %APPDATA%\dgt76t67sadt.exe
- 'up###e-cdn.com':80
- up###e-cdn.com/xtc/gate.php?hw###################################################################################
- DNS ASK up###e-cdn.com
- ClassName: 'Indicator' WindowName: '(null)'