Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] '{E14F58F1-154E-8D0A-756F-77A6B87C7842}' = '%APPDATA%\Miiryz\ofyl.exe'
- '%APPDATA%\Miiryz\ofyl.exe'
- '%APPDATA%\Miiryz\ofyl.exe'
- '<SYSTEM32>\cmd.exe' /c "%TEMP%\tmp_3ac5db03.bat"
- <SYSTEM32>\cmd.exe
- ClassName: 'OLLYDBG', WindowName: ''
- %HOMEPATH%\Local Settings\<INETFILES>\Content.IE5\KHMHGZ4F\g[1].htm
- %TEMP%\tmp_3ac5db03.bat
- %APPDATA%\Miiryz\ofyl.exe
- '2n######kogbiykd.onion.pw':80
- DNS ASK 2n######kogbiykd.onion.pw
- ClassName: 'Rock Debugger' WindowName: ''
- ClassName: 'ObsidianGUI' WindowName: ''
- ClassName: 'Zeta Debugger' WindowName: ''
- ClassName: 'WinDbgFrameClass' WindowName: ''
- ClassName: 'Immunity Debugger' WindowName: ''