Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Windows Defender' = '%APPDATA%\app\winlogon.exe.exe'
- %APPDATA%\app\winlogon.exe.exe
- %APPDATA%\Server.exe
- %APPDATA%\7za.exe "x" "-y" "%APPDATA%\Server.7z" "-pHVLnt5Dy"
- %APPDATA%\app\winlogon.exe.exe
- %APPDATA%\app\Set.bin
- <Текущая директория>\server.exe
- %APPDATA%\7za.exe
- %APPDATA%\Server.txt
- %APPDATA%\Server.7z
- %APPDATA%\Server.exe
- %APPDATA%\7za.exe
- 'bo#.###oksby.tkip.php':80
- 'bo#.####ksby.tkconnect.php':80
- bo#.###oksby.tkip.php/
- bo#.####ksby.tkconnect.php/
- DNS ASK bo#.###oksby.tkip.php
- DNS ASK bo#.####ksby.tkconnect.php