Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'C0FD6811' = '%APPDATA%\C0FD6811\bin.exe'
- '%WINDIR%\explorer.exe'
- <SYSTEM32>\cscript.exe
- %APPDATA%\C0FD6811\bin.exe
- %APPDATA%\C0FD6811\log.dat
- 'y1####947yh73y8i.cc':80
- http://y1####947yh73y8i.cc/n0tru2t76hw2edqj/
- DNS ASK y1####947yh73y8i.cc
- ClassName: 'Indicator' WindowName: ''