Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'WindowsServiceUpdate' = '%APPDATA%\crssn.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] '%APPDATA%\crssn.exe' = '%APPDATA%\crssn.exe:*:Enabled:WindowsServiceUpdate'
- %APPDATA%\crssn.exe
- %APPDATA%\crssn.exe
- %APPDATA%\crssn.exe
- 'te##.#anjsheri.com':81
- DNS ASK te##.#anjsheri.com