Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '{A269257C-9EFE-5C79-B303-A63978B2AEAE}' = '"%ALLUSERSPROFILE%\Application Data\{3E790D4C-B6CE-C069-B303-A63978B2AEAE}\93C6DDD3.exe"'
- '<SYSTEM32>\svchost.exe'
- <SYSTEM32>\svchost.exe
- %TEMP%\03A647F41.tmp
- %APPDATA%\state.tmp
- %ALLUSERSPROFILE%\Application Data\salt.dat
- %ALLUSERSPROFILE%\Application Data\{3E790D4C-B6CE-C069-B303-A63978B2AEAE}\93C6DDD3.exe
- '52.##.214.72':443
- '19#.#09.206.212':443
- 'ip##fo.io':443
- 'localhost':1037
- '15#.#5.175.225':443
- DNS ASK ip##fo.io
- ClassName: 'ЁжЂ|яяяяЈжЂ|«зЂ|+иЂ|юяяя' WindowName: 'ЁжЂ|яяяяЈжЂ|«зЂ|+иЂ|юяяя'
- ClassName: '???|???????|???|+??|????' WindowName: '???|???????|???|+??|????'