Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\RunOnce] 'Startup key' = '%HOMEPATH%\subfolder1\server.vbs'
- server.exe
- %HOMEPATH%\subfolder1\server.exe
- %HOMEPATH%\subfolder1\server.vbs
- 'dr##box.com':443
- 'uc#############ea8bfac1c156c.dl.dropboxusercontent.com':443
- '19#.5.99.29':2526
- DNS ASK dr##box.com
- DNS ASK uc#############ea8bfac1c156c.dl.dropboxusercontent.com
- '%HOMEPATH%\subfolder1\server.exe'