Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'loki' = '"%APPDATA%\Adobe\Acrobat\DC\Collab\_testorp.exe"'
- %TEMP%\_mei27602\crypto\cipher\_arc4.cp36-win_amd64.pyd
- %TEMP%\_mei12962\_cffi_backend.cp36-win_amd64.pyd
- %TEMP%\_mei12962\_bz2.pyd
- %TEMP%\_mei12962\vcruntime140.dll
- %APPDATA%\adobe\acrobat\dc\collab\cyclops_windows.exe
- %APPDATA%\adobe\acrobat\dc\collab\_testorp.exe
- %TEMP%\_mei27602\lib2to3\tests\data\readme
- %TEMP%\_mei27602\lib2to3\patterngrammar3.6.6.final.0.pickle
- %TEMP%\_mei27602\lib2to3\patterngrammar.txt
- %TEMP%\_mei12962\_decimal.pyd
- %TEMP%\_mei12962\_ctypes.pyd
- %TEMP%\_mei27602\base_library.zip
- %TEMP%\_mei27602\include\pyconfig.h
- %TEMP%\_mei27602\unicodedata.pyd
- %TEMP%\_mei27602\testorp.exe.manifest
- %TEMP%\_mei27602\select.pyd
- %TEMP%\_mei27602\python36.dll
- %TEMP%\_mei27602\pyexpat.pyd
- %TEMP%\_mei27602\_ssl.pyd
- %TEMP%\_mei27602\lib2to3\grammar3.6.6.final.0.pickle
- %TEMP%\_mei27602\crypto\hash\_ripemd160.cp36-win_amd64.pyd
- %TEMP%\_mei12962\_hashlib.pyd
- %TEMP%\_mei12962\cryptography-2.8-py3.6.egg-info\record
- %TEMP%\_mei12962\cryptography-2.8-py3.6.egg-info\metadata
- %TEMP%\_mei12962\cryptography-2.8-py3.6.egg-info\license.psf
- %TEMP%\_mei12962\cryptography-2.8-py3.6.egg-info\license.bsd
- %TEMP%\_mei12962\cryptography-2.8-py3.6.egg-info\license.apache
- %TEMP%\_mei12962\cryptography-2.8-py3.6.egg-info\license
- %TEMP%\_mei12962\cryptography-2.8-py3.6.egg-info\installer
- %TEMP%\_mei12962\cryptography-2.8-py3.6.egg-info\authors.rst
- %TEMP%\_mei12962\certifi\cacert.pem
- %TEMP%\_mei12962\base_library.zip
- %TEMP%\_mei12962\unicodedata.pyd
- %TEMP%\_mei12962\testorp.exe.manifest
- %TEMP%\_mei12962\select.pyd
- %TEMP%\_mei12962\python36.dll
- %TEMP%\_mei12962\pyexpat.pyd
- %TEMP%\_mei12962\cryptography\hazmat\bindings\_openssl.cp36-win_amd64.pyd
- %TEMP%\_mei12962\cryptography\hazmat\bindings\_constant_time.cp36-win_amd64.pyd
- %TEMP%\_mei12962\_ssl.pyd
- %TEMP%\_mei12962\_socket.pyd
- %TEMP%\_mei27602\_socket.pyd
- %TEMP%\_mei27602\lib2to3\grammar.txt
- %TEMP%\_mei27602\_multiprocessing.pyd
- %TEMP%\_mei27602\_lzma.pyd
- %TEMP%\_mei27602\_hashlib.pyd
- %TEMP%\_mei27602\crypto\cipher\_raw_ctr.cp36-win_amd64.pyd
- %TEMP%\_mei27602\crypto\hash\_blake2s.cp36-win_amd64.pyd
- %TEMP%\_mei27602\crypto\hash\_blake2b.cp36-win_amd64.pyd
- %TEMP%\_mei27602\crypto\cipher\_raw_ofb.cp36-win_amd64.pyd
- %TEMP%\_mei27602\crypto\cipher\_raw_ocb.cp36-win_amd64.pyd
- %TEMP%\_mei27602\crypto\cipher\_raw_eksblowfish.cp36-win_amd64.pyd
- %TEMP%\_mei27602\crypto\cipher\_raw_ecb.cp36-win_amd64.pyd
- %TEMP%\_mei27602\crypto\cipher\_raw_des3.cp36-win_amd64.pyd
- %TEMP%\_mei27602\crypto\cipher\_raw_des.cp36-win_amd64.pyd
- %TEMP%\_mei27602\crypto\cipher\_raw_cfb.cp36-win_amd64.pyd
- %TEMP%\_mei27602\crypto\hash\_md4.cp36-win_amd64.pyd
- %TEMP%\_mei27602\crypto\cipher\_raw_cbc.cp36-win_amd64.pyd
- %TEMP%\_mei27602\crypto\cipher\_raw_cast.cp36-win_amd64.pyd
- %TEMP%\_mei27602\crypto\cipher\_raw_blowfish.cp36-win_amd64.pyd
- %TEMP%\_mei27602\crypto\cipher\_raw_arc2.cp36-win_amd64.pyd
- %TEMP%\_mei27602\crypto\cipher\_raw_aesni.cp36-win_amd64.pyd
- %TEMP%\_mei27602\crypto\cipher\_raw_aes.cp36-win_amd64.pyd
- %TEMP%\_mei27602\crypto\cipher\_chacha20.cp36-win_amd64.pyd
- %TEMP%\_mei27602\crypto\cipher\_salsa20.cp36-win_amd64.pyd
- %TEMP%\_mei12962\cryptography-2.8-py3.6.egg-info\wheel
- %TEMP%\_mei12962\_lzma.pyd
- %TEMP%\_mei27602\crypto\hash\_md5.cp36-win_amd64.pyd
- %TEMP%\_mei27602\crypto\hash\_sha224.cp36-win_amd64.pyd
- %TEMP%\_mei27602\crypto\hash\_md2.cp36-win_amd64.pyd
- %TEMP%\_mei27602\_distutils_findvs.pyd
- %TEMP%\_mei27602\_decimal.pyd
- %TEMP%\_mei27602\_ctypes.pyd
- %TEMP%\_mei27602\_cffi_backend.cp36-win_amd64.pyd
- %TEMP%\_mei27602\_bz2.pyd
- %TEMP%\_mei27602\vcruntime140.dll
- %TEMP%\_mei27602\crypto\util\_strxor.cp36-win_amd64.pyd
- %TEMP%\_mei27602\crypto\util\_cpuid_c.cp36-win_amd64.pyd
- %TEMP%\_mei27602\crypto\publickey\_ec_ws.cp36-win_amd64.pyd
- %TEMP%\_mei27602\crypto\protocol\_scrypt.cp36-win_amd64.pyd
- %TEMP%\_mei27602\crypto\math\_modexp.cp36-win_amd64.pyd
- %TEMP%\_mei27602\crypto\hash\_poly1305.cp36-win_amd64.pyd
- %TEMP%\_mei27602\crypto\hash\_keccak.cp36-win_amd64.pyd
- %TEMP%\_mei27602\crypto\hash\_ghash_portable.cp36-win_amd64.pyd
- %TEMP%\_mei27602\crypto\hash\_ghash_clmul.cp36-win_amd64.pyd
- %TEMP%\_mei27602\crypto\hash\_sha512.cp36-win_amd64.pyd
- %TEMP%\_mei27602\crypto\hash\_sha384.cp36-win_amd64.pyd
- %TEMP%\_mei27602\crypto\hash\_sha256.cp36-win_amd64.pyd
- %TEMP%\_mei27602\crypto\hash\_sha1.cp36-win_amd64.pyd
- %TEMP%\_mei12962\cryptography-2.8-py3.6.egg-info\top_level.txt
- %TEMP%\_mei27602\base_library.zip
- %TEMP%\_mei27602\crypto\math\_modexp.cp36-win_amd64.pyd
- %TEMP%\_mei27602\crypto\protocol\_scrypt.cp36-win_amd64.pyd
- %TEMP%\_mei27602\crypto\publickey\_ec_ws.cp36-win_amd64.pyd
- %TEMP%\_mei27602\crypto\util\_cpuid_c.cp36-win_amd64.pyd
- %TEMP%\_mei27602\crypto\util\_strxor.cp36-win_amd64.pyd
- %TEMP%\_mei27602\include\pyconfig.h
- %TEMP%\_mei27602\lib2to3\grammar.txt
- %TEMP%\_mei27602\lib2to3\grammar3.6.6.final.0.pickle
- %TEMP%\_mei27602\lib2to3\patterngrammar.txt
- %TEMP%\_mei27602\lib2to3\patterngrammar3.6.6.final.0.pickle
- %TEMP%\_mei27602\lib2to3\tests\data\readme
- %TEMP%\_mei27602\crypto\hash\_sha384.cp36-win_amd64.pyd
- %TEMP%\_mei27602\crypto\hash\_sha512.cp36-win_amd64.pyd
- %TEMP%\_mei27602\pyexpat.pyd
- %TEMP%\_mei27602\testorp.exe.manifest
- %TEMP%\_mei27602\unicodedata.pyd
- %TEMP%\_mei27602\vcruntime140.dll
- %TEMP%\_mei27602\_bz2.pyd
- %TEMP%\_mei27602\_cffi_backend.cp36-win_amd64.pyd
- %TEMP%\_mei27602\_ctypes.pyd
- %TEMP%\_mei27602\_decimal.pyd
- %TEMP%\_mei27602\_distutils_findvs.pyd
- %TEMP%\_mei27602\_hashlib.pyd
- %TEMP%\_mei27602\_lzma.pyd
- %TEMP%\_mei27602\_multiprocessing.pyd
- %TEMP%\_mei27602\python36.dll
- %TEMP%\_mei27602\select.pyd
- %TEMP%\_mei27602\crypto\hash\_sha256.cp36-win_amd64.pyd
- %TEMP%\_mei27602\crypto\hash\_sha224.cp36-win_amd64.pyd
- %TEMP%\_mei27602\crypto\hash\_sha1.cp36-win_amd64.pyd
- %TEMP%\_mei27602\crypto\cipher\_chacha20.cp36-win_amd64.pyd
- %TEMP%\_mei27602\crypto\cipher\_raw_aes.cp36-win_amd64.pyd
- %TEMP%\_mei27602\crypto\cipher\_raw_aesni.cp36-win_amd64.pyd
- %TEMP%\_mei27602\crypto\cipher\_raw_arc2.cp36-win_amd64.pyd
- %TEMP%\_mei27602\crypto\cipher\_raw_blowfish.cp36-win_amd64.pyd
- %TEMP%\_mei27602\crypto\cipher\_raw_cast.cp36-win_amd64.pyd
- %TEMP%\_mei27602\crypto\cipher\_raw_cbc.cp36-win_amd64.pyd
- %TEMP%\_mei27602\crypto\cipher\_raw_cfb.cp36-win_amd64.pyd
- %TEMP%\_mei27602\crypto\cipher\_raw_ctr.cp36-win_amd64.pyd
- %TEMP%\_mei27602\crypto\cipher\_raw_des.cp36-win_amd64.pyd
- %TEMP%\_mei27602\crypto\cipher\_raw_des3.cp36-win_amd64.pyd
- %TEMP%\_mei27602\crypto\cipher\_raw_ecb.cp36-win_amd64.pyd
- %TEMP%\_mei27602\crypto\cipher\_arc4.cp36-win_amd64.pyd
- %TEMP%\_mei27602\crypto\cipher\_raw_eksblowfish.cp36-win_amd64.pyd
- %TEMP%\_mei27602\crypto\cipher\_raw_ofb.cp36-win_amd64.pyd
- %TEMP%\_mei27602\crypto\cipher\_salsa20.cp36-win_amd64.pyd
- %TEMP%\_mei27602\crypto\hash\_blake2b.cp36-win_amd64.pyd
- %TEMP%\_mei27602\crypto\hash\_blake2s.cp36-win_amd64.pyd
- %TEMP%\_mei27602\crypto\hash\_ghash_clmul.cp36-win_amd64.pyd
- %TEMP%\_mei27602\crypto\hash\_ghash_portable.cp36-win_amd64.pyd
- %TEMP%\_mei27602\crypto\hash\_keccak.cp36-win_amd64.pyd
- %TEMP%\_mei27602\crypto\hash\_md2.cp36-win_amd64.pyd
- %TEMP%\_mei27602\crypto\hash\_md4.cp36-win_amd64.pyd
- %TEMP%\_mei27602\crypto\hash\_md5.cp36-win_amd64.pyd
- %TEMP%\_mei27602\crypto\hash\_poly1305.cp36-win_amd64.pyd
- %TEMP%\_mei27602\crypto\hash\_ripemd160.cp36-win_amd64.pyd
- %TEMP%\_mei27602\crypto\cipher\_raw_ocb.cp36-win_amd64.pyd
- %TEMP%\_mei27602\_socket.pyd
- %TEMP%\_mei27602\_ssl.pyd
- 'localhost':8080
- http://ip##pi.com/json
- DNS ASK ip##pi.com
- '%APPDATA%\adobe\acrobat\dc\collab\_testorp.exe'
- '<SYSTEM32>\cmd.exe' /c "reg add HKCU\Software\Microsoft\Windows\CurrentVersion\Run /v loki /f /d "\"%APPDATA%\Adobe\Acrobat\DC\Collab\_testorp.exe\"""' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c "reg add HKCU\Software\Microsoft\Windows\CurrentVersion\Run /v loki /f /d "\"%APPDATA%\Adobe\Acrobat\DC\Collab\_testorp.exe\"""
- '<SYSTEM32>\reg.exe' add HKCU\Software\Microsoft\Windows\CurrentVersion\Run /v loki /f /d "\"%APPDATA%\Adobe\Acrobat\DC\Collab\_testorp.exe\""