Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Microsoft Defender' = '"<LS_APPDATA>\%USERNAME%Controle.exe"'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Microsoft Defender' = '"<LS_APPDATA>\%USERNAME%Controle.exe"'
- <LS_APPDATA>\%USERNAME%Controle.exe
- 'ho#####ndo.from-nv.com':82
- DNS ASK ho#####ndo.from-nv.com