Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Adobe' = '%TEMP%\InstallDir\silver.exe'
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run] 'Windows Update' = '%TEMP%\InstallDir\silver.exe'
- %APPDATA%\microsoft\windows\start menu\programs\startup\microsoft corporation.exe
- %TEMP%\installdir\silver.exe
- '0.###.ngrok.io':11026
- DNS ASK 0.###.ngrok.io
- '%TEMP%\installdir\silver.exe'