Техническая информация
- %WINDIR%\microsoft.net\framework\v4.0.30319\regasm.exe
- %APPDATA%\thewaloff\filingood.exe
- %APPDATA%\thewaloff\testoviyjuki.exe
- %LOCALAPPDATA%\microsoft\windows\history\history.ie5\mshist012020072520200726\index.dat
- http://of###ewall.top/brazi/filingood.exe
- http://of###ewall.top/brazi/testoviyjuki.exe
- http://ch#####.amazonaws.com/
- http://www.ge###ugin.net/json.gp?ip###############
- http://45.##.229.57:81/IRemotePanel via 45.##.229.57
- DNS ASK ip###ger.org
- DNS ASK of###ewall.top
- DNS ASK ap#.ip.sb
- DNS ASK ch#####.amazonaws.com
- DNS ASK wh###.iana.org
- DNS ASK WH###.RIPE.NET
- DNS ASK ge###ugin.net
- ClassName: 'AutoHotkey' WindowName: '<Полный путь к файлу>'
- ClassName: 'DDEMLMom' WindowName: ''
- ClassName: 'IEFrame' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebCheckMonitor' WindowName: ''
- ClassName: 'Static' WindowName: ''
- '%APPDATA%\thewaloff\testoviyjuki.exe'
- '%WINDIR%\microsoft.net\framework\v4.0.30319\regasm.exe'