Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run] 'Policies' = '%APPDATA%\859902.exe'
- %WINDIR%\syswow64\svchost.exe
- cvtre.exe
- %TEMP%\behtr.exe
- %TEMP%\cvtre.exe
- %APPDATA%\859902.exe
- %APPDATA%\859902.exe
- %TEMP%\cvtre.exe
- DNS ASK bl###.zapto.org
- '%TEMP%\behtr.exe'
- '%TEMP%\cvtre.exe'
- '%WINDIR%\syswow64\svchost.exe'