Техническая информация
- '%TEMP%\loremoment.exe'
- '<SYSTEM32>\DllHost.exe' /pid=0xb64 /log
- '<SYSTEM32>\conhost.exe' /Processid:{F9717507-6651-4EDB-BFF7-AE615179BCCF}
- <Служебный элемент>
- %TEMP%\loremoment.exe
- %TEMP%\LOREE50E.txt
- '17#.#9.58.27':443
- '21#.69.7.79':443
- '65.##.201.39':443
- '69.#.48.221':443
- '67.##7.228.144':443
- '38.##4.60.82':443
- '17#.#9.58.15':443
- '69.#.204.37':443
- '93.#7.3.169':443
- '79.##1.2.254':443
- '67.##9.166.113':443
- '19#.#06.166.22':443
- '17#.#9.58.28':443
- '21#.#45.211.242':443
- '79.##1.42.247':443
- '17#.#19.10.23':443
- DNS ASK dn#.##ftncsi.com
- DNS ASK ic###azip.com
- ClassName: 'Shell_TrayWnd' WindowName: ''