Техническая информация
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\] 'windows1' = '%APPDATA%\Install\Host.exe'
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Active Setup\Installed Components\{256C14W2-4307-17L5-O833-2WK3KRN38HN2}] 'StubPath' = '"%APPDATA%\Install\Host.exe"'
- '%APPDATA%\876543.exe'
- 876543.exe
- host.exe
- %APPDATA%\876543.exe
- %APPDATA%\install\host.exe
- '18#.#65.153.221':8973
- http://jo###lawi.com/none/bill.txt
- DNS ASK jo###lawi.com
- '%APPDATA%\install\host.exe'
- '%CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe' -Embedding