Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\RunOnce] 'Startup key' = '%TEMP%\subfolder1\Yourphone.vbs'
- '' (загружен из сети Интернет)
- 'C:\users\public\908.exe'
- yourphone.exe
- C:\users\public\908.exe
- %TEMP%\subfolder1\yourphone.exe
- %TEMP%\subfolder1\yourphone.vbs
- %HOMEPATH%\remcos\logs.dat
- 're#####ealth.ddns.net':39777
- http://bi#.ly/2C0jX71
- http://li###nboard.pt/cli/yppersteprstelig.txt
- http://10#.#9.91.158/WEALTHREMCOS_UNVtHEtvA173.bin
- DNS ASK bi#.ly
- DNS ASK li###nboard.pt
- DNS ASK re#####ealth.ddns.net
- '%TEMP%\subfolder1\yourphone.exe'
- '%CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe' -Embedding