Техническая информация
- %APPDATA%\D4T4.liv
- %APPDATA%\Adobe_Prefs.json
- %APPDATA%\Microsoft\Internet Explorer\brndlog.txt в %APPDATA%\Microsoft\Internet Explorer\brndlog.txt.king_ouroboros
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\cert8.db в %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\cert8.db.king_ouroboros
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\key3.db в %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\key3.db.king_ouroboros
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\pluginreg.dat в %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\pluginreg.dat.king_ouroboros
- %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\secmod.db в %APPDATA%\Mozilla\Firefox\Profiles\cwdgt0y8.default\secmod.db.king_ouroboros
- 'wp#d':80
- 'ki####uroboros.gq':20
- http://11#.#11.111.1/wpad.dat via wp#d
- DNS ASK wp#d
- DNS ASK ki####uroboros.gq