Техническая информация
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\] 'NetWire' = '%APPDATA%\Install\Host.exe'
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Active Setup\Installed Components\{OCP3V85B-15UB-6C01-O4Q2-SDT76BAWRI30}] 'StubPath' = '"%APPDATA%\Install\Host.exe"'
- host.exe
- %APPDATA%\install\host.exe
- 'pl####.duckdns.org':32123
- http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/02FAF3E291435468607857694DF5E45B68851868.crt
- http://oc##.#ectigo.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRDC9IOTxN6GmyRjyTl2n4yTUczyAQUjYxexFStiuF36Zv5mwXhuAGNYeECECUTgfQsc%2BcBwNBMQNWQl0M%3D
- DNS ASK me###fire.com
- DNS ASK oc##.#ectigo.com
- DNS ASK do######2267.mediafire.com
- DNS ASK pl####.duckdns.org
- '%APPDATA%\install\host.exe'