Техническая информация
- '%TEMP%\garafot.exe'
- '<SYSTEM32>\DllHost.exe' /pid=0x87c /log
- '<SYSTEM32>\conhost.exe' /Processid:{F9717507-6651-4EDB-BFF7-AE615179BCCF}
- <Служебный элемент>
- %TEMP%\garafot.exe
- %TEMP%\GAR_77D8.log
- '64.##4.235.251':443
- '20#.#93.86.226':443
- '20#.#93.86.222':443
- '20#.#93.67.172':443
- '21#.#45.211.242':443
- '18#.#64.97.60':443
- '20#.#93.86.41':443
- '20#.#93.86.225':443
- '18#.#64.97.232':443
- '68.##0.55.120':443
- '68.##0.58.11':443
- '18#.#64.107.103':443
- '20#.#93.89.252':443
- '18#.#64.97.235':443
- '20#.#93.86.223':443
- '18#.#64.97.237':443
- DNS ASK dn#.##ftncsi.com
- DNS ASK ic###azip.com
- ClassName: 'Shell_TrayWnd' WindowName: ''