Техническая информация
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\] 'windows' = '%APPDATA%\Install\Host.exe'
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Active Setup\Installed Components\{TK1A7HT7-DQYO-67A2-ANU2-MW11C1A1UU6E}] 'StubPath' = '"%APPDATA%\Install\Host.exe"'
- '%APPDATA%\7654567999.exe'
- 7654567999.exe
- host.exe
- %APPDATA%\7654567999.exe
- %APPDATA%\install\host.exe
- '79.##4.225.35':8687
- http://af######ocurementagency.com/admin/admin.exe
- DNS ASK af######ocurementagency.com
- '%APPDATA%\install\host.exe'
- '%CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe' -Embedding