Техническая информация
- <SYSTEM32>\svchost.exe
- %TEMP%\dllhost.exe
- %TEMP%\easyhook.dll
- %TEMP%\easyhook64.dll
- %TEMP%\easyload64.dll
- %TEMP%\barmonitor.dll
- %LOCALAPPDATA%\barhelper.dll
- http://ch######.zhuge666.com:21700/Update/AppLoader via ch#####g.zhuge666.com
- http://ch######.zhuge666.com:21700/Update/App via ch#####g.zhuge666.com
- http://ch######.zhuge666.com:21700/Update/PlugSetup via ch#####g.zhuge666.com
- DNS ASK ch#####g.zhuge666.com
- DNS ASK zh######.##s-cn-beijing.aliyuncs.com
- '%TEMP%\dllhost.exe'
- '%TEMP%\dllhost.exe' ' (со скрытым окном)
- '<SYSTEM32>\svchost.exe' -k imgsvr