Техническая информация
- %WINDIR%\Tasks\MsSystemWatcher.job
- %APPDATA%\msnet\b772ef49.exe
- %APPDATA%\msnet\FAQ
- 'ap#.#pify.org':443
- 'ap#.ip.sb':443
- 'id##t.me':443
- 'my####rnalip.com':443
- 'ch#####.amazonaws.com':80
- 'ip##ho.net':80
- 'ip##fo.io':80
- 'ap#.#pify.org':80
- 'ic###azip.com':80
- 'my####rnalip.com':80
- 'wt###myip.com':80
- http://ch#####.amazonaws.com/
- http://ip##ho.net/plain
- http://ip##fo.io/ip
- http://ap#.#pify.org/
- http://ic###azip.com/
- http://my####rnalip.com/raw
- http://wt###myip.com/text
- DNS ASK ap#.#pify.org
- DNS ASK ap#.ip.sb
- DNS ASK id##t.me
- DNS ASK www.my####rnalip.com
- DNS ASK ch#####.amazonaws.com
- DNS ASK ip##ho.net
- DNS ASK ip##fo.io
- DNS ASK ic###azip.com
- DNS ASK my####rnalip.com
- DNS ASK wt###myip.com
- ClassName: 'LoWindow' WindowName: 'LoWindowApp 1.0'
- '%APPDATA%\msnet\b772ef49.exe' and Settings\\%USERNAME%\\Application Data\\msnet\\b772ef49.exe\"