Техническая информация
- [<HKLM>\System\CurrentControlSet\Services\jzZE32E] 'Start' = '00000001'
- [<HKLM>\System\CurrentControlSet\Services\jzZE32E] 'ImagePath' = '%TEMP%\jzZE32E.dat'
- [<HKLM>\SYSTEM\ControlSet001\services\jzZE32E] 'ImagePath' = '%TEMP%\jzZE32E.dat'
- %TEMP%\jzze32f.exe
- %TEMP%\jzze32e.dat
- %TEMP%\jzze32f.exe
- http://41##.cn:10100/dfghb via 41#u.cn
- http://im####.baidu.com/tieba/pic/item/1c950a7b02087bf47e5ec2bcfdd3572c11dfcf31.jpg
- http://bl###########31.cos.ap-hongkong.myqcloud.com/xccdd
- http://im####.baidu.com/tieba/pic/item/377adab44aed2e73d54210798801a18b87d6fa38.jpg
- http://im####.baidu.com/tieba/pic/item/91ef76c6a7efce1b162d0e9ea051f3deb48f6564.jpg
- http://im###.baidu.com/forum/pic/item/5cb450600c33874417c641745e0fd9f9d62aa0cc.jpg
- http://im####.baidu.com/tieba/pic/item/86d6277f9e2f0708ccc33a55e624b899a801f2a5.jpg
- http://im###.baidu.com/forum/pic/item/e26d970a304e251fa9df1d61aa86c9177e3e53dc.jpg
- /api/Service/GetInfo_ext_v1 via 41#u.cn
- http://41##.cn:10100/api/servicetwo/getinfo via 41#u.cn
- /api/Service/GetResponeseResult via 41#u.cn
- DNS ASK 41#u.cn
- DNS ASK im####.baidu.com
- DNS ASK bl###########31.cos.ap-hongkong.myqcloud.com
- DNS ASK im###.baidu.com
- '%TEMP%\jzze32f.exe' %TEMP%\jzZE32E.dat
- '%WINDIR%\syswow64\cmd.exe' /c del %TEMP%\jzZE32F.exe >> NUL' (со скрытым окном)
- '%WINDIR%\syswow64\cmd.exe' /c del %TEMP%\jzZE32F.exe >> NUL