Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'scrss' = '%APPDATA%\dotNET.lnk'
- ClassName: 'OLLYDBG', WindowName: ''
- ClassName: 'GBDYLLO', WindowName: ''
- ClassName: 'pediy06', WindowName: ''
- ClassName: 'FilemonClass', WindowName: ''
- ClassName: '', WindowName: 'File Monitor - Sysinternals: www.sysinternals.com'
- ClassName: 'PROCMON_WINDOW_CLASS', WindowName: ''
- ClassName: '', WindowName: 'Process Monitor - Sysinternals: www.sysinternals.com'
- ClassName: 'RegmonClass', WindowName: ''
- ClassName: '', WindowName: 'Registry Monitor - Sysinternals: www.sysinternals.com'
- %APPDATA%\lsass.exe
- http://u9####79.beget.tech/trgfa7yj3xmno1eyapsworjhat9dehqo0/2djaeg167zmlc5trf25nxpbn9uyy06zxsgv4cuqfk269c4edvhrotj3x8pp1fr3onl0aohcwb3w4ut7zx65/3b4e0f7ae3a14acc128fc984b8876b8296ad9907.php?da#...
- http://we###nglilu.ru/v2cm48io1bbpetq9shkl0at4rvisv8opq2wpgm9sodceysk6orpgu3qqua6sv/ygamdefd/fyatxzn586k7cahcdvz39qniwffdxebejwnsgpidwj6nmasjj7tstxy3rhs44y/557b895cd6b28f530e026723a1f9df74.php?...
- http://we###nglilu.ru/v2cm48io1bbpetq9shkl0at4rvisv8opq2wpgm9sodceysk6orpgu3qqua6sv/ygamdefd/fyatxzn586k7cahcdvz39qniwffdxebejwnsgpidwj6nmasjj7tstxy3rhs44y/aa197feb78ec6227e15dace393ef71b94227e...
- http://ip##fo.io/ip
- DNS ASK u9####79.beget.tech
- DNS ASK we###nglilu.ru
- DNS ASK ip##fo.io
- ClassName: '18467-41' WindowName: ''