Техническая информация
- <SYSTEM32>\tasks\doorbell windows application
- '<SYSTEM32>\rundll32.exe' C:\isNaOBb\xwZGXKO\xiQSmPU.dll,DllRegisterServer
- <SYSTEM32>\wermgr.exe
- C:\isnaobb\xwzgxko\xiqsmpu.dll
- %APPDATA%\doorbell\qzxiqsmpulu.dog
- %APPDATA%\doorbell\urls.ini
- http://23.##.231.200/images/footer1.dll
- DNS ASK my####rnalip.com
- '<SYSTEM32>\rundll32.exe' C:\isNaOBb\xwZGXKO\xiQSmPU.dll,DllRegisterServer' (со скрытым окном)
- '<SYSTEM32>\wermgr.exe'