Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] '{12BA05DD-53B2-CBE4-F6EF-D971BD38962A}' = '%APPDATA%\Ysanka\qoopr.exe'
- '%APPDATA%\Ysanka\qoopr.exe'
- '%APPDATA%\Ysanka\qoopr.exe'
- '<SYSTEM32>\cmd.exe' /c "%TEMP%\tmp_72d63002.bat"
- <SYSTEM32>\cmd.exe
- ClassName: 'OLLYDBG', WindowName: ''
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\KHMHGZ4F\g[1].htm
- %TEMP%\tmp_72d63002.bat
- %APPDATA%\Ysanka\qoopr.exe
- 'xp######ayiqxmzl.onion.pw':80
- DNS ASK xp######ayiqxmzl.onion.pw
- ClassName: 'Rock Debugger' WindowName: ''
- ClassName: 'ObsidianGUI' WindowName: ''
- ClassName: 'Zeta Debugger' WindowName: ''
- ClassName: 'WinDbgFrameClass' WindowName: ''
- ClassName: 'Immunity Debugger' WindowName: ''