Техническая информация
- '%APPDATA%\ugotrollx84819.com'
- %WINDIR%\explorer.exe
- %WINDIR%\syswow64\mstsc.exe
- ugotrollx84819.com
- iexplore.exe
- firefox.exe
- Процесс iexplore.exe, модуль wininet.dll
- Процесс firefox.exe, модуль nss3.dll
- %APPDATA%\ugotrollx84819.com
- %WINDIR%\serviceprofiles\networkservice\appdata\locallow\microsoft\cryptneturlcache\metadata\f0accf77cdcbff39f6191887f6d2d357
- %WINDIR%\serviceprofiles\networkservice\appdata\locallow\microsoft\cryptneturlcache\content\f0accf77cdcbff39f6191887f6d2d357
- %APPDATA%\ugotrollx84819.com
- http://ab##s.ir/ugobuild/Trommesyg1.exe
- http://oc##.thawte.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQwF4prw9S7mCbCEHD%2Fyl6nWPkczAQUe1tFz6%2FOy3r9MZIaarbzRutXSFACEEeXTXhzpbyrDS%2BzcBkvzl4%3D
- DNS ASK ab##s.ir
- DNS ASK ho####nsoltani.ir
- DNS ASK oc##.thawte.com
- '%CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe' -Embedding
- '%WINDIR%\syswow64\mstsc.exe'
- '%WINDIR%\syswow64\cmd.exe' del "%APPDATA%\ugotrollx84819.com"