Техническая информация
- http://84.##.248.166/owen/owen1_.exe как %appdata%\owen1_.exe
- [<HKCU>\Software\RimArts\B2\Settings]
- [<HKCU>\SOFTWARE\Martin Prikryl\WinSCP 2\Sessions]
- [<HKCU>\Software\FTPWare\COREFTP\Sites]
- %APPDATA%\thunderbird\profiles.ini
- %TEMP%\abctfhghghghghš.sct
- %APPDATA%\owen1_.exe
- %TEMP%\ixp000.tmp\c88xbxoqise.tmp
- %TEMP%\ixp000.tmp\qjmfjol0dq6.exe
- %TEMP%\ixp000.tmp\1u8cx0zdxp6.exe
- %TEMP%\ixp000.tmp\qjmfjol0dq6.exe
- %TEMP%\ixp000.tmp\1u8cx0zdxp6.exe в %TEMP%\tmpg428.tmp
- http://84.##.248.166/owen/owen1_.exe
- '%APPDATA%\owen1_.exe'
- '%TEMP%\ixp000.tmp\qjmfjol0dq6.exe' -decrypt -key rf4saq675ks -infile c88xbxoqise.tmp -outfile 1u8cx0zdxp6.exe
- '%TEMP%\ixp000.tmp\1u8cx0zdxp6.exe'
- '%TEMP%\ixp000.tmp\qjmfjol0dq6.exe' -decrypt -key rf4saq675ks -infile c88xbxoqise.tmp -outfile 1u8cx0zdxp6.exe' (со скрытым окном)
- '%TEMP%\ixp000.tmp\1u8cx0zdxp6.exe' ' (со скрытым окном)