Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'iconrdb' = '%APPDATA%\iconrdb.exe'
- <Имя диска съемного носителя>:\images.exe
- %APPDATA%\iconrdb.exe
- 'ft#.###esharesgroup.com':21
- http://google.com/
- http://www.google.com/
- http://ti####aresgroup.com/wp-admin/includes/class-wip.txt
- DNS ASK google.com
- DNS ASK ti####aresgroup.com
- DNS ASK ft#.###esharesgroup.com