Техническая информация
- %LOCALAPPDATA%\reportevent.log
- %LOCALAPPDATA%\nfvo4gtuiicw5varaeqqv\jwndlkafg5g9wowxrq.js
- %APPDATA%\gbioytzymblfeupk.zip
- %APPDATA%\9tcfhf~1\gxcvetvqvwvebjikiiflxqkiss.db
- %APPDATA%\9tcfhf~1\ywtvnz.db
- %APPDATA%\9tcfhf~1\gxcvetvqvwvebjikiiflxqkiss.exe
- %LOCALAPPDATA%\nfvo4gtuiicw5varaeqqv\jwndlkafg5g9wowxrq.js
- %APPDATA%\gbioytzymblfeupk.zip
- http://19#.#92.20.113/Avovjyahrddqolkpz/Ghcpxtmnblsluv/Zewmssztkzx/Mfebpgulyjwybfopg/Gbioytzymblfeupk.db
- '<SYSTEM32>\wscript.exe' "%LOCALAPPDATA%\nFVO4GtuiICW5VAraeqqV\jwndLKAfG5g9woWXRq.js"
- '<SYSTEM32>\logonui.exe' /flags:0x1