Техническая информация
- [<HKLM>\System\CurrentControlSet\Services\httpapi] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\httpapi] 'ImagePath' = '"%WINDIR%\SysWOW64\perfhost\httpapi.exe"'
- 'httpapi' "%WINDIR%\SysWOW64\perfhost\httpapi.exe"
- 'httpapi' %WINDIR%\SysWOW64\perfhost\httpapi.exe
- из <Полный путь к файлу> в %WINDIR%\syswow64\perfhost\httpapi.exe
- '18#.#89.249.2':80
- '59.##8.253.194':8080
- http://59.###.253.194:8080/maNEE8ezj/LqKJ3ZDxtfLpRW/ via 59.##8.253.194