Техническая информация
- [<HKLM>\System\CurrentControlSet\Services\IKEEXT] 'Start' = '00000002'
- http://www.bo####rnote.kro.kr/
- http://cr#####er.dothome.co.kr/ban.txt
- http://cr#####er.dothome.co.kr/fivembooster/20200809/up.txt
- http://cr#####er.dothome.co.kr/fivembooster/20200809/on.txt
- DNS ASK bo####rnote.kro.kr
- DNS ASK cr#####er.dothome.co.kr
- '%WINDIR%\syswow64\cmd.exe' /C POWERCFG /setactive 8c5e7fda-e8bf-4a96-9a85-a6e23a8c635c' (со скрытым окном)
- '%WINDIR%\syswow64\cmd.exe' /c netsh advfirewall set currentprofile state off' (со скрытым окном)
- '%WINDIR%\syswow64\cmd.exe' /C POWERCFG /setactive 8c5e7fda-e8bf-4a96-9a85-a6e23a8c635c
- '%WINDIR%\syswow64\cmd.exe' /c netsh advfirewall set currentprofile state off
- '%WINDIR%\syswow64\netsh.exe' advfirewall set currentprofile state off
- '%WINDIR%\syswow64\powercfg.exe' /setactive 8c5e7fda-e8bf-4a96-9a85-a6e23a8c635c