Техническая информация
- %PROGRAMDATA%\ec40016aefa10c1b7a71ef6a56c6d383
- %PROGRAMDATA%\81f7f8f911\bdif.exe
- http://ba#####thmeter.online/gBvsce2/cred.dll
- DNS ASK ch###er.monster
- DNS ASK ba#####thmeter.online
- DNS ASK re####elookup.icu
- '%PROGRAMDATA%\81f7f8f911\bdif.exe'
- '%WINDIR%\syswow64\reg.exe' ADD "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders" /f /v Startup /t REG_SZ /d %PROGRAMDATA%\81f7f8f911