Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\RunOnce] 'udplacered' = '%HOMEPATH%\Ddslejersamino\Unhelpingh7.vbs'
- 'C:\users\public\908.exe'
- unhelpingh7.exe
- %LOCALAPPDATA%\microsoft\windows\inetcookies\20gelqk9.txt
- C:\users\public\908.exe
- %HOMEPATH%\ddslejersamino\unhelpingh7.exe
- %HOMEPATH%\ddslejersamino\unhelpingh7.vbs
- http://bi#.ly/3dfDUEu
- DNS ASK bi#.ly
- DNS ASK so####rion.com.ar
- DNS ASK pr######usmoney.duckdns.org
- '::####:224.0.0.252':5355
- '%HOMEPATH%\ddslejersamino\unhelpingh7.exe'
- '%CommonProgramFiles(x86)%\microsoft shared\equation\eqnedt32.exe' -Embedding