Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'wmpnetwrk.exe' = '%APPDATA%\wmpnetwrk.exe'
- %APPDATA%\wmpnetwrk.exe
- %TEMP%\ws2_32.lib
- <Текущая директория>\libeay32.dll
- %APPDATA%\wmpnetwrk.exe
- 'br#.to':80
- 'ti##url.ms':80
- 'ti#y.cc':80
- 'ti##url.com':80
- br#.to/08017af4
- br#.to/4fa64ba0
- ti##url.ms/08017af4
- ti##url.ms/4fa64ba0
- ti#y.cc/08017af4
- ti#y.cc/4fa64ba0
- ti##url.com/08017af4
- ti##url.com/4fa64ba0
- DNS ASK ti##url.com
- DNS ASK br#.to
- DNS ASK ti##url.ms
- DNS ASK ti#y.cc
- DNS ASK ti###b.nist.gov
- 'localhost':1037
- 'ti###b.nist.gov':123
- ClassName: 'Indicator' WindowName: ''