Техническая информация
- [<HKCU>\software\Microsoft\Windows\CurrentVersion\Run] '7DT9YVL7ILTY' = '<SYSTEM32>\cmd.exe /k cd\ & cd 7DT9YVL7ILTY & 7DT9YVL7ILTY.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'n0R9C0f7' = '<SYSTEM32>\cmd.exe /k cd\ & cd 7DT9YVL7ILTY\ & cmoiwdobnt.exe'
- <SYSTEM32>\cmd.exe
- C:\users\public\documents\7dt9yvl7ilty_7dt9yvl7ilty_7dt9yvl7ilty.zip
- C:\7dt9yv~1\a.png
- C:\7dt9yv~1\msvcp120.dll
- C:\7dt9yv~1\msvcr120.dll
- C:\7dt9yv~1\rundll32.exe
- C:\7dt9yvl7ilty\cmoiwdobnt.exe
- C:\7dt9yvl7ilty\avira.oe.nativecore.dll.cfg
- C:\users\public\documents\7dt9yvl7ilty_7dt9yvl7ilty_7dt9yvl7ilty.zip
- http://bl#####20.servebeer.com/mdl/img.jpg
- DNS ASK bl#####20.servebeer.com
- DNS ASK docs.google.com
- DNS ASK cl######ss.webcindario.com
- ClassName: '' WindowName: 'Aplicativo ItaГє'
- ClassName: 'SunAwtFrame' WindowName: ''
- '<SYSTEM32>\cmd.exe' /k cd\ & cd c:\7DT9YVL7ILTY & 7DT9YVL7ILTY.exe' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /k cd\ & cd c:\7DT9YVL7ILTY & 7DT9YVL7ILTY.exe