Техническая информация
- [<HKLM>\System\CurrentControlSet\Services\WindowsAccessBridge] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\WindowsAccessBridge] 'ImagePath' = '"<SYSTEM32>\WindowsAccessBridge\WindowsAccessBridge.exe"'
- из <Полный путь к файлу> в <SYSTEM32>\windowsaccessbridge\windowsaccessbridge.exe
- '17#.#21.229.86':80
- '18#.#90.47.173':80
- '91.##6.4.234':443
- http://18#.#90.47.173/n4qm8JFrt4ooFZYRGX/4leBlmNkYbf2J/ebmtpJBHRF8D1MIXY1G/c3sMAciq/HZ3D5ukWYtAY1NsDHr/
- http://91.###.4.234:443/0L0NR/oca6gn/nqWk1qfJWY3oPbxeGv/02FBUaw74xm/ via 91.##6.4.234