Техническая информация
- '<SYSTEM32>\mshta.exe' https://web-link.gq/base
- %APPDATA%\microsoft\crypto\rsa\s-1-5-21-1960123792-2022915161-3775307078-1001\e30681cad9c91e9a242e7536ba7ed6ed_36d1130a-ac2e-44f7-9dc1-e424fbcbe0ee
- http://oc##.###-x3.letsencrypt.org/MFMwUTBPME0wSzAJBgUrDgMCGgUABBR%2B5mrncpqz%2FPiiIGRsFqEtYHEIXQQUqEpqYwR93brm0Tm3pkVl7%2FOo7KECEgOjjcpJxumDalw0ta6T69vk%2FQ%3D%3D
- http://we##link.ml/home/login.aspx
- http://we##link.ml/documents/parcel.html
- http://we##link.ml/login.aspx
- http://we##link.ml/index.html
- DNS ASK we##link.gq
- DNS ASK oc##.###-x3.letsencrypt.org
- DNS ASK we##link.ml