Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'imapi.exe' = '%APPDATA%\Microsoft\rsh.exe'
- %WINDIR%\Explorer.EXE
- %APPDATA%\Microsoft\rsh.exe
- 'r1#####hbq.oogagh.su':443
- 'df#####txh.bo0keego.cc':443
- '1m####.thepohzi.su':443
- DNS ASK r1#####hbq.oogagh.su
- DNS ASK df#####txh.bo0keego.cc
- DNS ASK 1m####.thepohzi.su
- ClassName: 'Indicator' WindowName: ''