Техническая информация
- http://sa##pem.com/osta.exe как %appdata%\osta.exe
- osta.exe
- %TEMP%\abctfhghghghghВЈ.sct
- %PROGRAMDATA%\hrjytrj.cmd
- %APPDATA%\osta.exe
- %APPDATA%\microsoft\windows\cookies\user@google[1].txt
- 'as#######2020.quicksytes.com':3360
- http://sa##pem.com/osta.exe
- DNS ASK sa##pem.com
- DNS ASK do#########ocs.googleusercontent.com
- DNS ASK as#######2020.quicksytes.com
- '%APPDATA%\osta.exe'