Техническая информация
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\] 'Client Server Runtime Subsystem' = '"%PROGRAMDATA%\Windows\csrss.exe"'
- '%TEMP%\radc0866.tmp'
- <LS_APPDATA>\microsoft\windows\<INETFILES>\content.ie5\caasbycl\1c[1].jpg
- %TEMP%\radc0866.tmp
- %PROGRAMDATA%\windows\csrss.exe
- %TEMP%\6893a5~1\state.tmp
- %TEMP%\6893a5~1\unverified-microdesc-consensus.tmp
- %TEMP%\6893a5~1\cached-certs.tmp
- %TEMP%\6893a5~1\cached-microdesc-consensus.tmp
- %TEMP%\6893a5~1\unverified-microdesc-consensus
- %TEMP%\6893a5~1\state.tmp в %TEMP%\6893a5~1\state
- %TEMP%\6893a5~1\unverified-microdesc-consensus.tmp в %TEMP%\6893a5~1\unverified-microdesc-consensus
- %TEMP%\6893a5~1\cached-certs.tmp в %TEMP%\6893a5~1\cached-certs
- %TEMP%\6893a5~1\cached-microdesc-consensus.tmp в %TEMP%\6893a5~1\cached-microdesc-consensus
- 'localhost':49161
- '76.##.17.194':9090
- '12#.31.0.39':9101
- '17#.#5.193.9':80
- http://mc##yan.com/wp-content/themes/twentynineteen/sass/blocks/1c.jpg
- DNS ASK mc##yan.com
- '<SYSTEM32>\cmd.exe' /c %TEMP%\radC0866.tmp' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c %TEMP%\radC0866.tmp