Техническая информация
- [<HKLM>\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\] 'Images' = '%ALLUSERSPROFILE%\images.exe'
- '%TEMP%\build_deobfuscated.exe'
- '%APPDATA%\build.exe'
- '%ALLUSERSPROFILE%\images.exe'
- %TEMP%\build_deobfuscated.exe
- %APPDATA%\build.exe
- %ALLUSERSPROFILE%\images.exe
- '<LOCALNET>.8.102':5200