Техническая информация
- %WINDIR%\tasks\lkjihg.job
- <SYSTEM32>\tasks\lkjihg
- %PROGRAMDATA%\vekqxf\lkjihg.exe
- http://19#.#8.81.140/tor/status-vote/current/consensus
- http://86.#9.21.38/tor/status-vote/current/consensus
- DNS ASK ad###t127ds.xyz
- DNS ASK ad###ace147.xyz
- DNS ASK ap#.#pify.org
- '%PROGRAMDATA%\vekqxf\lkjihg.exe' start
- '%PROGRAMDATA%\vekqxf\lkjihg.exe' start' (со скрытым окном)