Техническая информация
- %WINDIR%\tasks\openvpn-gui.job
- <SYSTEM32>\tasks\openvpn-gui
- %TEMP%\amblers.dll
- '<SYSTEM32>\notepad.exe'
- <SYSTEM32>\notepad.exe
- %TEMP%\amblers.dll
- %TEMP%\12277e.jpg
- %LOCALAPPDATA%\google\chrome\user data\default\extension state\openvpn-gui.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extension state\libcrypto-1_1.dll
- http://oc##.#tartssl.com/sub/class2/code/ca/MEMwQTA%2FMD0wOzAJBgUrDgMCGgUABBQSOgrhRCSnWfKxoWTjWxhk8hga9AQU0E4PQJlsuEsZbzsouODjiAc0qrcCAhAV
- DNS ASK i.##b.co
- DNS ASK oc##.#tartssl.com